CVE-2018-5999
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/01/2018
Last modified:
03/10/2019
Description
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests continues even if authentication fails.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:asus:asuswrt:*:*:*:*:*:*:*:* | 3.0.0.4.384_10007 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://blogs.securiteam.com/index.php/archives/3589
- https://github.com/pedrib/PoC/blob/master/advisories/asuswrt-lan-rce.txt
- https://raw.githubusercontent.com/pedrib/PoC/master/exploits/metasploit/asuswrt_lan_rce.rb
- https://www.exploit-db.com/exploits/43881/
- https://www.exploit-db.com/exploits/44176/



