Critical severity9.8NVD Advisory· Published Jan 22, 2018· Updated Jun 17, 2026
CVE-2018-6000
CVE-2018-6000
Description
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and launch an SSH daemon (or enable infosvr command mode), and consequently obtain remote administrative access, via a crafted request. This is available to unauthenticated attackers in conjunction with CVE-2018-5999.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
5- blogs.securiteam.com/index.php/archives/3589nvdExploitTechnical DescriptionThird Party Advisory
- github.com/pedrib/PoC/blob/master/advisories/asuswrt-lan-rce.txtnvdExploitThird Party Advisory
- raw.githubusercontent.com/pedrib/PoC/master/exploits/metasploit/asuswrt_lan_rce.rbnvdExploitThird Party Advisory
- www.exploit-db.com/exploits/43881/nvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/44176/nvd
News mentions
1- What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)SANS Internet Storm Center · Jun 25, 2026