CVE-2018-8826

CRITICAL

ASUS RT-AC Series Firmware - Remote Code Execution

Title source: llm
STIX 2.1

Description

ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N600 routers with firmware before 3.0.0.4.380.10446; RT-AC55U and RT-AC55UHP routers with firmware before 3.0.0.4.382.50276; RT-AC86U and RT-AC2900 routers with firmware before 3.0.0.4.384.20648; and possibly other RT-series routers allow remote attackers to execute arbitrary code via unspecified vectors.

References (14)

Core 14
Core References
Vendor Advisory x_refsource_confirm
https://www.asus.com/Networking/RT-AC2900/HelpDesk_BIOS/
Vendor Advisory x_refsource_confirm
https://www.asus.com/us/Networking/RTN66W/HelpDesk_BIOS/
Vendor Advisory x_refsource_confirm
https://www.asus.com/us/Networking/RTAC66U/HelpDesk_BIOS/

Scores

CVSS v3 9.8
EPSS 0.0555
EPSS Percentile 90.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (13)
asus/rt-ac1200_firmware 3.0.0.4.380.10446
asus/rt-ac1750_firmware 3.0.0.4.380.8228
asus/rt-ac2900_firmware 3.0.0.4.384.20648
asus/rt-ac51u_firmware 3.0.0.4.380.8228
asus/rt-ac52u_b1_firmware 3.0.0.4.380.10446
asus/rt-ac55u_firmware 3.0.0.4.382.50276
asus/rt-ac55uhp_firmware 3.0.0.4.382.50276
asus/rt-ac58u_firmware 3.0.0.4.380.8228
asus/rt-ac66u_firmware 3.0.0.4.380.8228
asus/rt-ac86u_firmware 3.0.0.4.384.20648
... and 3 more
Published Apr 20, 2018
Tracked Since Feb 18, 2026