Description
An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has an eval call, as demonstrated by the /6/api.php?function=command&class=remote&Cc='ls' URI. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution
Published: 2018-10-15
Score: 9.8 Critical
EPSS: 12.7% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Asuswrt-merlin Project Rt-ac1900 Rt-ac1900 Firmware Rt-ac2900 Rt-ac2900 Firmware Rt-ac3100 Rt-ac3100 Firmware Rt-ac3200 Rt-ac3200 Firmware Rt-ac5300 Rt-ac5300 Firmware Rt-ac56u Rt-ac56u Firmware Rt-ac66u B1 Rt-ac66u B1 Firmware Rt-ac68p Rt-ac68p Firmware Rt-ac68u Rt-ac68u Firmware Rt-ac68uf Rt-ac68uf Firmware Rt-ac86u Rt-ac86u Firmware Rt-ac87 Rt-ac87 Firmware Rt-ac88u Rt-ac88u Firmware Rt Ac1900p Rt Ac1900p Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-16T16:28:44.054Z

Reserved: 2018-10-15T00:00:00.000Z

Link: CVE-2018-18319

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-10-15T06:29:00.607

Modified: 2024-11-21T03:55:42.133

Link: CVE-2018-18319

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses