CVE-2018-5999
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 87%
from disclosure to weapon0 days
Published on NVDJan 22
1st PoCJan 22
metasploitJan 22
VulnCheck+3037d
exploitation probability
87%top 1% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests continues even if authentication fails.
Affected products
n/a · n/apublic PoCs found — 4✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/44176exploitdbwww.exploit-db.com/exploits/43881unverifiedcve_referencewww.exploit-db.com/exploits/43881/unverifiedcve_referencewww.exploit-db.com/exploits/44176/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://blogs.securiteam.com/index.php/archives/3589https://github.com/pedrib/PoC/blob/master/advisories/asuswrt-lan-rce.txthttps://raw.githubusercontent.com/pedrib/PoC/master/exploits/metasploit/asuswrt_lan_rce.rbhttps://www.exploit-db.com/exploits/43881/https://www.exploit-db.com/exploits/44176/