CVE-2018-8877
Last modified
CVE-2018-8877 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network IP address ranges by reading the new_lan_ip variable on the error_page.htm page.. EPSS estimates a 1.44% chance of exploitation in the next 30 days.
Description
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network IP address ranges by reading the new_lan_ip variable on the error_page.htm page.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Asus | Asus Firmware | < 3.0.0.4.382.50470 |
| Asuswrt-Merlin | Asuswrt-Merlin | < 384.4 |
References
- https://github.com/outofhere/Research/blob/master/2018/Asus/cve_notes.mdThird Party Advisory
- https://github.com/outofhere/Research/blob/master/2018/Asus/cve_notes.mdThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-8877?
How severe is CVE-2018-8877?
How do I fix CVE-2018-8877?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-8871In Delta Electronics Automation TPEditor version 1.89 or pri…9.8
- CVE-2018-8872In Schneider Electric Triconex Tricon MP model 3008 firmware…
- CVE-2018-8873In 2345 Security Guard 3.6, the driver file (2345NetFirewall…
- CVE-2018-8874In 2345 Security Guard 3.6, the driver file (2345Wrath.sys) …
- CVE-2018-8875In 2345 Security Guard 3.6, the driver file (2345Wrath.sys) …
- CVE-2018-8876In 2345 Security Guard 3.6, the driver file (2345Wrath.sys) …
- CVE-2018-8878Information disclosure in Asuswrt-Merlin firmware for ASUS d…5.3
- CVE-2018-8879Stack-based buffer overflow in Asuswrt-Merlin firmware for A…9.8
- CVE-2018-8880Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doe…
- CVE-2018-8881Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer …
- CVE-2018-8882Netwide Assembler (NASM) 2.13.02rc2 has a stack-based buffer…
- CVE-2018-8883Netwide Assembler (NASM) 2.13.02rc2 has a buffer over-read i…
Are you affected by CVE-2018-8877?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
