ZeroHour

CVE-2018-8878

CVSS 3.1
5.3 medium
EPSS
1%p73
Published
()
Modified
Description

Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page.

Vendors
asuswrt-merlinasus
Products
asuswrt-merlin, asus firmware
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.