CVE-2018-20334
9.8
CRITICAL · CVSS 3.1 · EPSS 3.8% (pctl 90)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.77% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-03-20 |
| Last modified | 2026-06-17 |
Affected (40)
| Vendor | Product |
|---|---|
| asus | asuswrt |
| asus | gt-ac2900 |
| asus | gt-ac5300 |
| asus | gt-ax11000 |
| asus | rt-ac1200 |
| asus | rt-ac1200 v2 |
| asus | rt-ac1200g |
| asus | rt-ac1200ge |
| asus | rt-ac1750 |
| asus | rt-ac1750 b1 |
| asus | rt-ac1900p |
| asus | rt-ac3100 |
| asus | rt-ac3200 |
| asus | rt-ac51u |
| asus | rt-ac5300 |
| asus | rt-ac55u |
| asus | rt-ac56r |
| asus | rt-ac56s |
| asus | rt-ac56u |
| asus | rt-ac66r |
| asus | rt-ac66u |
| asus | rt-ac66u b1 |
| asus | rt-ac66u-b1 |
| asus | rt-ac68p |
| asus | rt-ac68u |
| asus | rt-ac86u |
| asus | rt-ac87u |
| asus | rt-ac88u |
| asus | rt-acrh12 |
| asus | rt-acrh13 |
| asus | rt-ax3000 |
| asus | rt-ax56u |
| asus | rt-ax58u |
| asus | rt-ax88u |
| asus | rt-ax92u |
| asus | rt-g32 |
| asus | rt-n10\+d1 |
| asus | rt-n10e |
| asus | rt-n14u |
| asus | rt-n16 |
→ the Explorer · watch your stack · NVD