CVE-2018-5999
CRITICAL EXPLOITEDAsusWRT <3.0.0.4.384_10007 - Info Disclosure
Title source: llmExploitation Summary
CVE-2018-5999 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including Metasploit, Pedro Ribeiro.
AI-analyzed exploit summary This Metasploit module exploits CVE-2018-6000 in AsusWRT routers by setting the `ateCommand_flag` via a POST request to `/vpnupload.cgi` and then sending a UDP packet to port 9999 to execute arbitrary commands as root. It starts a telnetd service on a random port for interactive shell access.
Description
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests continues even if authentication fails.
Exploits (2)
This Metasploit module exploits CVE-2018-6000 in AsusWRT routers by setting the `ateCommand_flag` via a POST request to `/vpnupload.cgi` and then sending a UDP packet to port 9999 to execute arbitrary commands as root. It starts a telnetd service on a random port for interactive shell access.
This is a detailed writeup describing two vulnerabilities (CVE-2018-5999 and CVE-2018-6000) in AsusWRT routers, including an authentication bypass and unauthenticated NVRAM configuration manipulation leading to remote code execution. The document explains the technical details, exploitation steps, and references related tools like a Metasploit module.
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H