← Vulnerability feed

Vulnerability record · CVE-2018-20334 · published 20 March 2020

CVE-2018-20334: Asuswrt os command injection vulnerability

Asus · Asuswrt

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.

9.8 CVSS 3.1 Critical EPSS 3.8% · top 10.4% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
3.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://starlabs.sg/advisories/18-20334/ ExploitThird Party Advisory
https://starlabs.sg/advisories/18-20334/ ExploitThird Party Advisory

Track CVE-2018-20334 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26376Asuswrt out-of-bounds write vulnerabilityA memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior t…EPSS 1.4%9.8CVE-2018-5999AsusWRT HTTPd processes POST requests after failed authenticationAsusWRT before 3.0.0.4.384_10007 has a flaw in the handle_request function in router/httpd/httpd.c where POST request processing continues even when …EPSS 87%analysed9.8CVE-2018-6000AsusWRT vpnupload.cgi missing authorization allows admin password resetThe do_vpnupload_post function in router/httpd/web.c in AsusWRT before 3.0.0.4.384_10007 lets a request set NVRAM configuration values without author…EPSS 85%analysed9.6CVE-2017-15655Asuswrt memory buffer overflow vulnerabilityMultiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.37…EPSS 3.1%8.8CVE-2017-15653Asuswrt insufficient session expiration vulnerabilityImproper administrator IP validation after his login in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allows an unau…EPSS 2.0%8.8CVE-2017-15656Asuswrt insufficiently protected credentials vulnerabilityPassword are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt.EPSS 1.5%8.3CVE-2017-15654Asuswrt vulnerabilityHighly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allow gaining administrative rout…EPSS 2.1%7.5CVE-2018-20333Asuswrt information exposure vulnerabilityAn issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to t…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2018-20334), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.