CVE-2018-8877
Last modified
CVE-2018-8877 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network IP address ranges by reading the new_lan_ip variable on the error_page.htm page.. EPSS estimates a 1.44% chance of exploitation in the next 30 days.
Description
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network IP address ranges by reading the new_lan_ip variable on the error_page.htm page.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Asus | Asus Firmware | < 3.0.0.4.382.50470 |
| Asuswrt-Merlin | Asuswrt-Merlin | < 384.4 |
References
- https://github.com/outofhere/Research/blob/master/2018/Asus/cve_notes.mdThird Party Advisory
- https://github.com/outofhere/Research/blob/master/2018/Asus/cve_notes.mdThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-8877?
How severe is CVE-2018-8877?
How do I fix CVE-2018-8877?
Are you affected by CVE-2018-8877?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
