VYPR
Medium severity5.3NVD Advisory· Published Feb 27, 2020· Updated Jun 17, 2026

CVE-2018-8878

CVE-2018-8878

Description

Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page.

Affected products

5
  • Rmerl/Asuswrt Merlinllm-create2 versions
    <384.4+ 1 more
    • (no CPE)range: <384.4
    • cpe:2.3:o:asuswrt-merlin:asuswrt-merlin:*:*:*:*:*:*:*:*range: <384.4
  • Asus/Asus Firmwarellm-fuzzy2 versions
    <3.0.0.4.382.50470+ 1 more
    • (no CPE)range: <3.0.0.4.382.50470
    • cpe:2.3:o:asus:asus_firmware:*:*:*:*:*:*:*:*range: <3.0.0.4.382.50470
  • ASUS/Asuswrt-Merlin firmwaredescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.