peter bassill · operator
$ cve CVE-2018-6000 JSON

CVE-2018-6000 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 85.2% (pctl 100)

Patch early

A public exploit exists.

Description

An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and launch an SSH daemon (or enable infosvr command mode), and consequently obtain remote administrative access, via a crafted request. This is available to unauthenticated attackers in conjunction with CVE-2018-5999.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS85.16% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-862
On CISA KEVno
Public exploityes
Published2018-01-22
Last modified2026-06-17

Affected (1)

VendorProduct
asusasuswrt

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD