Description
An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has an eval call, as demonstrated by the /6/api.php?function=command&class=remote&Cc='ls' URI. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Subscriptions
Asuswrt-merlin Project
Subscribe
Rt-ac1900
Subscribe
Rt-ac1900 Firmware
Subscribe
Rt-ac2900
Subscribe
Rt-ac2900 Firmware
Subscribe
Rt-ac3100
Subscribe
Rt-ac3100 Firmware
Subscribe
Rt-ac3200
Subscribe
Rt-ac3200 Firmware
Subscribe
Rt-ac5300
Subscribe
Rt-ac5300 Firmware
Subscribe
Rt-ac56u
Subscribe
Rt-ac56u Firmware
Subscribe
Rt-ac66u B1
Subscribe
Rt-ac66u B1 Firmware
Subscribe
Rt-ac68p
Subscribe
Rt-ac68p Firmware
Subscribe
Rt-ac68u
Subscribe
Rt-ac68u Firmware
Subscribe
Rt-ac68uf
Subscribe
Rt-ac68uf Firmware
Subscribe
Rt-ac86u
Subscribe
Rt-ac86u Firmware
Subscribe
Rt-ac87
Subscribe
Rt-ac87 Firmware
Subscribe
Rt-ac88u
Subscribe
Rt-ac88u Firmware
Subscribe
Rt Ac1900p
Subscribe
Rt Ac1900p Firmware
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T16:28:44.054Z
Reserved: 2018-10-15T00:00:00.000Z
Link: CVE-2018-18319
No data.
Status : Modified
Published: 2018-10-15T06:29:00.607
Modified: 2024-11-21T03:55:42.133
Link: CVE-2018-18319
No data.
OpenCVE Enrichment
No data.
Weaknesses