CVE-2018-8877
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network IP address ranges by reading the new_lan_ip variable on the error_page.htm page.
- Affected products
- Asus Firmware, Asuswrt-Merlin
- Asus Asus Firmware
- < 3.0.0.4.382.50470
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 1.5% (71th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2020-02-27
CVE-2018-8877 at NVD
No indexed exploits for CVE-2018-8877 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2018-8877 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.