CVE-2018-20333

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
20/03/2020
Last modified:
23/03/2020

Description

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to the router and if there are apps installed on the router.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:asus:asuswrt:3.0.0.4.384.20308:*:*:*:*:*:*:*
cpe:2.3:h:asus:gt-ac2900:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:gt-ac5300:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:gt-ax11000:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac1200:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac1200_v2:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac1200g:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac1200ge:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac1750:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac1750_b1:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac1900p:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac3100:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac3200:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac51u:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac5300:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools