CVE Feed

    Dashboard / CVE / CVE-2018-20334

    CVE-2018-20334

    An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.

    Published:Mar 20, 2020
    Last Modified:Nov 21, 2024
    EPS:Mar 20, 2020
    EPSS Score:0.03696
    CVSS Score:9.8

    Affected Products

    Vendor
    Asus
    Product
    Asuswrt
    Vendor
    Asus
    Product
    Gt-ac2900
    Vendor
    Asus
    Product
    Gt-ac5300
    Vendor
    Asus
    Product
    Gt-ax11000
    Vendor
    Asus
    Product
    Rt-ac1200
    Vendor
    Asus
    Product
    Rt-ac1200 V2
    Vendor
    Asus
    Product
    Rt-ac1200g
    Vendor
    Asus
    Product
    Rt-ac1200ge
    Vendor
    Asus
    Product
    Rt-ac1750
    Vendor
    Asus
    Product
    Rt-ac1750 B1
    Vendor
    Asus
    Product
    Rt-ac1900p
    Vendor
    Asus
    Product
    Rt-ac3100
    Vendor
    Asus
    Product
    Rt-ac3200
    Vendor
    Asus
    Product
    Rt-ac51u
    Vendor
    Asus
    Product
    Rt-ac5300
    Vendor
    Asus
    Product
    Rt-ac55u
    Vendor
    Asus
    Product
    Rt-ac56r
    Vendor
    Asus
    Product
    Rt-ac56s
    Vendor
    Asus
    Product
    Rt-ac56u
    Vendor
    Asus
    Product
    Rt-ac66r
    Vendor
    Asus
    Product
    Rt-ac66u
    Vendor
    Asus
    Product
    Rt-ac66u-b1
    Vendor
    Asus
    Product
    Rt-ac66u B1
    Vendor
    Asus
    Product
    Rt-ac68p
    Vendor
    Asus
    Product
    Rt-ac68u
    Vendor
    Asus
    Product
    Rt-ac86u
    Vendor
    Asus
    Product
    Rt-ac87u
    Vendor
    Asus
    Product
    Rt-ac88u
    Vendor
    Asus
    Product
    Rt-acrh12
    Vendor
    Asus
    Product
    Rt-acrh13
    Vendor
    Asus
    Product
    Rt-ax3000
    Vendor
    Asus
    Product
    Rt-ax56u
    Vendor
    Asus
    Product
    Rt-ax58u
    Vendor
    Asus
    Product
    Rt-ax88u
    Vendor
    Asus
    Product
    Rt-ax92u
    Vendor
    Asus
    Product
    Rt-g32
    Vendor
    Asus
    Product
    Rt-n10\+d1
    Vendor
    Asus
    Product
    Rt-n10e
    Vendor
    Asus
    Product
    Rt-n14u
    Vendor
    Asus
    Product
    Rt-n16
    Vendor
    Asus
    Product
    Rt-n19
    Vendor
    Asus
    Product
    Rt-n56r
    Vendor
    Asus
    Product
    Rt-n56u
    Vendor
    Asus
    Product
    Rt-n600
    Vendor
    Asus
    Product
    Rt-n65u
    Vendor
    Asus
    Product
    Rt-n66r
    Vendor
    Asus
    Product
    Rt-n66u

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High