CVE-2018-6000

Scores

EPSS

0.907high90.7%
0%20%40%60%80%100%

Percentile: 90.7%

CVSS

9.8critical3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
10.0

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Description

An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and launch an SSH daemon (or enable infosvr command mode), and consequently obtain remote administrative access, via a crafted request. This is available to unauthenticated attackers in conjunction with CVE-2018-5999.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-862

Exploits

Exploit ID: 43881

Source: exploitdb

URL: https://www.exploit-db.com/exploits/43881

Exploit ID: 44176

Source: exploitdb

URL: https://www.exploit-db.com/exploits/44176

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: asuswrt

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:asus:asuswrt:*:*:*:*:*:*:*:*",      "versionEndExcluding": "3.0.0.4.384_10007",      "vulnerable": true    }  ],  "operator": "OR"}

Source: nvd

End of list