{
    "id": "CVE-2018-9285",
    "published": "2018-04-04 19:29:00",
    "last_modified": "2026-06-17 02:06:21",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.0",
    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-78",
    "description": "Main_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices before 3.0.0.4.384_10007; RT-N18U devices before 3.0.0.4.382.39935; RT-AC87U and RT-AC3200 devices before 3.0.0.4.382.50010; and RT-AC5300 devices before 3.0.0.4.384.20287 allows OS command injection via the pingCNT and destIP fields of the SystemCmd variable.",
    "epss_score": "0.03557",
    "epss_percentile": "0.89020",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-09 18:17:21",
    "priority": {
        "rank": 3,
        "label": "In your normal cycle",
        "why": "Critical by CVSS (9.8), but no sign of active exploitation."
    },
    "products": [
        {
            "vendor": "asus",
            "product": "rt-ac1900"
        },
        {
            "vendor": "asus",
            "product": "rt-ac1900_firmware"
        },
        {
            "vendor": "asus",
            "product": "rt-ac2900"
        },
        {
            "vendor": "asus",
            "product": "rt-ac2900_firmware"
        },
        {
            "vendor": "asus",
            "product": "rt-ac3100"
        },
        {
            "vendor": "asus",
            "product": "rt-ac3100_firmware"
        },
        {
            "vendor": "asus",
            "product": "rt-ac3200"
        },
        {
            "vendor": "asus",
            "product": "rt-ac3200_firmware"
        },
        {
            "vendor": "asus",
            "product": "rt-ac5300"
        },
        {
            "vendor": "asus",
            "product": "rt-ac5300_firmware"
        },
        {
            "vendor": "asus",
            "product": "rt-ac66u"
        },
        {
            "vendor": "asus",
            "product": "rt-ac66u_firmware"
        },
        {
            "vendor": "asus",
            "product": "rt-ac68u"
        },
        {
            "vendor": "asus",
            "product": "rt-ac68u_firmware"
        },
        {
            "vendor": "asus",
            "product": "rt-ac86u"
        },
        {
            "vendor": "asus",
            "product": "rt-ac86u_firmware"
        },
        {
            "vendor": "asus",
            "product": "rt-ac87u"
        },
        {
            "vendor": "asus",
            "product": "rt-ac87u_firmware"
        },
        {
            "vendor": "asus",
            "product": "rt-ac88u"
        },
        {
            "vendor": "asus",
            "product": "rt-ac88u_firmware"
        },
        {
            "vendor": "asus",
            "product": "rt-n18u"
        },
        {
            "vendor": "asus",
            "product": "rt-n18u_firmware"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "http://packetstormsecurity.com/files/160049/ASUS-TM-AC1900-Arbitrary-Command-Execution.html",
        "https://fortiguard.com/zeroday/FG-VD-17-216",
        "https://www.fortinet.com/blog/threat-research/fortiguard-labs-discovers-vulnerability-in-asus-router.html",
        "http://packetstormsecurity.com/files/160049/ASUS-TM-AC1900-Arbitrary-Command-Execution.html",
        "https://fortiguard.com/zeroday/FG-VD-17-216",
        "https://www.fortinet.com/blog/threat-research/fortiguard-labs-discovers-vulnerability-in-asus-router.html"
    ]
}