peter bassill · operator
$ cve CVE-2018-20334 JSON

CVE-2018-20334

9.8
CRITICAL · CVSS 3.1 · EPSS 3.8% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.77% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2020-03-20
Last modified2026-06-17

Affected (40)

VendorProduct
asusasuswrt
asusgt-ac2900
asusgt-ac5300
asusgt-ax11000
asusrt-ac1200
asusrt-ac1200 v2
asusrt-ac1200g
asusrt-ac1200ge
asusrt-ac1750
asusrt-ac1750 b1
asusrt-ac1900p
asusrt-ac3100
asusrt-ac3200
asusrt-ac51u
asusrt-ac5300
asusrt-ac55u
asusrt-ac56r
asusrt-ac56s
asusrt-ac56u
asusrt-ac66r
asusrt-ac66u
asusrt-ac66u b1
asusrt-ac66u-b1
asusrt-ac68p
asusrt-ac68u
asusrt-ac86u
asusrt-ac87u
asusrt-ac88u
asusrt-acrh12
asusrt-acrh13
asusrt-ax3000
asusrt-ax56u
asusrt-ax58u
asusrt-ax88u
asusrt-ax92u
asusrt-g32
asusrt-n10\+d1
asusrt-n10e
asusrt-n14u
asusrt-n16

References

→ the Explorer  ·  watch your stack  ·  NVD