← Vulnerability feed

Vulnerability record · CVE-2018-5999 · published 22 January 2018

CVE-2018-5999: AsusWRT HTTPd processes POST requests after failed authentication

Asus · Asuswrt

AsusWRT before 3.0.0.4.384_10007 has a flaw in the handle_request function in router/httpd/httpd.c where POST request processing continues even when authentication fails. This lets unauthenticated requests reach functionality that should require a valid login, which matters because the router's management interface is the control point for the whole device.

9.8 CVSS 3.0 Critical EPSS 87% · top 0.3%
9.8CVSS 3.0 base score, v2 10.0
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests continues even if authentication fails.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 3.0 rates this 9.8 with no authentication or interaction required, and public exploit code plus a very high EPSS score make exploitation likely for exposed devices.

What it is

AsusWRT before 3.0.0.4.384_10007 has a flaw in the handle_request function in router/httpd/httpd.c where POST request processing continues even when authentication fails. This lets unauthenticated requests reach functionality that should require a valid login, which matters because the router's management interface is the control point for the whole device.

Impact

An attacker gains unauthenticated access to POST-handling functionality on the router, with the potential for full compromise of confidentiality, integrity and availability given the CVSS 3.0 base score of 9.8.

Attack surface

Reachable over the network via HTTP POST requests to the router's httpd service; the CVSS vector AV:N/AC:L/PR:N/UI:N indicates no authentication and no user interaction are required.

Exploitation

Public exploit code exists, including Metasploit and Exploit-DB entries, and EPSS is 0.87264 (99.7th percentile); the CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded here.

What to do

  • Upgrade AsusWRT to 3.0.0.4.384_10007 or later as the primary fix.
  • If immediate upgrade is not possible, disable remote/WAN administration and restrict the router's web interface to trusted LAN hosts only.
  • Change default administrative credentials and disable any unused management services on the device.
  • Segment or isolate the router's management interface from untrusted networks until patched.

Detection

  • Monitor httpd logs and network traffic for POST requests to the router's web interface that are followed by successful responses despite failed or absent authentication.
  • Alert on unexpected POST requests originating from WAN-side or non-administrative source addresses.
  • Watch for known exploit payload patterns from the public Metasploit module and Exploit-DB entries against the router's httpd.
  • Audit router configuration changes and unexpected process activity that could indicate post-exploitation use of the bypass.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-5999 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26376Asuswrt out-of-bounds write vulnerabilityA memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior t…EPSS 1.3%9.8CVE-2018-20334Asuswrt os command injection vulnerabilityAn issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell me…EPSS 3.9%9.8CVE-2018-6000AsusWRT vpnupload.cgi missing authorization allows admin password resetThe do_vpnupload_post function in router/httpd/web.c in AsusWRT before 3.0.0.4.384_10007 lets a request set NVRAM configuration values without author…EPSS 85%analysed9.6CVE-2017-15655Asuswrt memory buffer overflow vulnerabilityMultiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.37…EPSS 3.1%8.8CVE-2017-15653Asuswrt insufficient session expiration vulnerabilityImproper administrator IP validation after his login in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allows an unau…EPSS 2.0%8.8CVE-2017-15656Asuswrt insufficiently protected credentials vulnerabilityPassword are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt.EPSS 1.5%8.3CVE-2017-15654Asuswrt vulnerabilityHighly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allow gaining administrative rout…EPSS 2.1%7.5CVE-2018-20333Asuswrt information exposure vulnerabilityAn issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to t…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2018-5999), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.