CVE-2018-18320
An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because exec.php has a popen call. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution
Published:Oct 15, 2018
Last Modified:Nov 21, 2024
EPS:Oct 15, 2018
EPSS Score:0.07498
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Asuswrt-merlin Project
Product
Rt-ac1900
Asuswrt-merlin Project
Rt-ac1900
Vendor
Asuswrt-merlin Project
Product
Rt-ac1900 Firmware
Asuswrt-merlin Project
Rt-ac1900 Firmware
Vendor
Asuswrt-merlin Project
Product
Rt-ac2900
Asuswrt-merlin Project
Rt-ac2900
Vendor
Asuswrt-merlin Project
Product
Rt-ac2900 Firmware
Asuswrt-merlin Project
Rt-ac2900 Firmware
Vendor
Asuswrt-merlin Project
Product
Rt-ac3100
Asuswrt-merlin Project
Rt-ac3100
Vendor
Asuswrt-merlin Project
Product
Rt-ac3100 Firmware
Asuswrt-merlin Project
Rt-ac3100 Firmware
Vendor
Asuswrt-merlin Project
Product
Rt-ac3200
Asuswrt-merlin Project
Rt-ac3200
Vendor
Asuswrt-merlin Project
Product
Rt-ac3200 Firmware
Asuswrt-merlin Project
Rt-ac3200 Firmware
Vendor
Asuswrt-merlin Project
Product
Rt-ac5300
Asuswrt-merlin Project
Rt-ac5300
Vendor
Asuswrt-merlin Project
Product
Rt-ac5300 Firmware
Asuswrt-merlin Project
Rt-ac5300 Firmware
Vendor
Asuswrt-merlin Project
Product
Rt-ac56u
Asuswrt-merlin Project
Rt-ac56u
Vendor
Asuswrt-merlin Project
Product
Rt-ac56u Firmware
Asuswrt-merlin Project
Rt-ac56u Firmware
Vendor
Asuswrt-merlin Project
Product
Rt-ac66u B1
Asuswrt-merlin Project
Rt-ac66u B1
Vendor
Asuswrt-merlin Project
Product
Rt-ac66u B1 Firmware
Asuswrt-merlin Project
Rt-ac66u B1 Firmware
Vendor
Asuswrt-merlin Project
Product
Rt-ac68p
Asuswrt-merlin Project
Rt-ac68p
Vendor
Asuswrt-merlin Project
Product
Rt-ac68p Firmware
Asuswrt-merlin Project
Rt-ac68p Firmware
Vendor
Asuswrt-merlin Project
Product
Rt-ac68u
Asuswrt-merlin Project
Rt-ac68u
Vendor
Asuswrt-merlin Project
Product
Rt-ac68u Firmware
Asuswrt-merlin Project
Rt-ac68u Firmware
Vendor
Asuswrt-merlin Project
Product
Rt-ac68uf
Asuswrt-merlin Project
Rt-ac68uf
Vendor
Asuswrt-merlin Project
Product
Rt-ac68uf Firmware
Asuswrt-merlin Project
Rt-ac68uf Firmware
Vendor
Asuswrt-merlin Project
Product
Rt-ac86u
Asuswrt-merlin Project
Rt-ac86u
Vendor
Asuswrt-merlin Project
Product
Rt-ac86u Firmware
Asuswrt-merlin Project
Rt-ac86u Firmware
Vendor
Asuswrt-merlin Project
Product
Rt-ac87
Asuswrt-merlin Project
Rt-ac87
Vendor
Asuswrt-merlin Project
Product
Rt-ac87 Firmware
Asuswrt-merlin Project
Rt-ac87 Firmware
Vendor
Asuswrt-merlin Project
Product
Rt-ac88u
Asuswrt-merlin Project
Rt-ac88u
Vendor
Asuswrt-merlin Project
Product
Rt-ac88u Firmware
Asuswrt-merlin Project
Rt-ac88u Firmware
Vendor
Asuswrt-merlin Project
Product
Rt Ac1900p
Asuswrt-merlin Project
Rt Ac1900p
Vendor
Asuswrt-merlin Project
Product
Rt Ac1900p Firmware
Asuswrt-merlin Project
Rt Ac1900p Firmware
Exploits
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
