CVE-2018-8879
Stack-based buffer overflow in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to execute arbitrary code by providing a long string to the blocking.asp page via a GET or POST request. Vulnerable parameters are flag, mac, and cat_id.
- Affected products
- Asus, Asuswrt-Merlin
- Asus rt-ac66u Firmware
- < 3.0.0.4.382.50470
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 17.2% (97th percentile)
- Weakness
- CWE-787
- NVD status
- Modified
- Published
- 2019-11-21
CVE-2018-8879 at NVD
No indexed exploits for CVE-2018-8879 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2018-8879 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.