← Vulnerability feed

Vulnerability record · CVE-2018-6000 · published 22 January 2018

CVE-2018-6000: AsusWRT vpnupload.cgi missing authorization allows admin password reset

Asus · Asuswrt

The do_vpnupload_post function in router/httpd/web.c in AsusWRT before 3.0.0.4.384_10007 lets a request set NVRAM configuration values without authorization. An attacker can use this to set the admin password and start an SSH daemon or enable infosvr command mode, gaining remote administrative control of the router.

9.8 CVSS 3.0 Critical EPSS 85% · top 0.3% CWE-862 · Missing authorization
9.8CVSS 3.0 base score, v2 10.0
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and launch an SSH daemon (or enable infosvr command mode), and consequently obtain remote administrative access, via a crafted request. This is available to unauthenticated attackers in conjunction with CVE-2018-5999.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no privileges or user interaction required, public exploit code, and full administrative compromise of the device.

What it is

The do_vpnupload_post function in router/httpd/web.c in AsusWRT before 3.0.0.4.384_10007 lets a request set NVRAM configuration values without authorization. An attacker can use this to set the admin password and start an SSH daemon or enable infosvr command mode, gaining remote administrative control of the router.

Impact

An attacker gains full remote administrative access to the router, including the ability to change the admin password and enable remote services such as SSH. This yields complete compromise of confidentiality, integrity and availability of the device.

Attack surface

Reachable over the network via a crafted HTTP request to vpnupload.cgi; the CVSS vector shows no privileges and no user interaction required. Per the description, unauthenticated exploitation depends on chaining with CVE-2018-5999.

Exploitation

Not listed in CISA KEV, but EPSS is 0.85161 (99.7th percentile) and multiple references are tagged Exploit, including Metasploit and Exploit-DB entries, indicating public exploit code exists.

What to do

  • Update AsusWRT to version 3.0.0.4.384_10007 or later, which is the fixed release named in the advisory.
  • If immediate patching is not possible, disable remote access to the router web interface and restrict administrative access to trusted internal networks only.
  • Change the router admin password after patching and disable any SSH daemon or infosvr command mode that is not required.
  • Segment or isolate router management interfaces from untrusted networks and monitor for unexpected configuration changes.

Detection

  • Monitor router and web logs for requests to vpnupload.cgi, especially POST requests from unexpected or external sources.
  • Alert on unexpected changes to NVRAM configuration, admin credentials, or enabling of SSH or infosvr services.
  • Watch for new or unexpected SSH daemon activity or inbound SSH connections to the router.
  • Correlate vpnupload.cgi access with CVE-2018-5999 exploitation attempts in the same session or timeframe.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-6000 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26376Asuswrt out-of-bounds write vulnerabilityA memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior t…EPSS 1.3%9.8CVE-2018-20334Asuswrt os command injection vulnerabilityAn issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell me…EPSS 3.9%9.8CVE-2018-5999AsusWRT HTTPd processes POST requests after failed authenticationAsusWRT before 3.0.0.4.384_10007 has a flaw in the handle_request function in router/httpd/httpd.c where POST request processing continues even when …EPSS 87%analysed9.6CVE-2017-15655Asuswrt memory buffer overflow vulnerabilityMultiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.37…EPSS 3.1%8.8CVE-2017-15653Asuswrt insufficient session expiration vulnerabilityImproper administrator IP validation after his login in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allows an unau…EPSS 2.0%8.8CVE-2017-15656Asuswrt insufficiently protected credentials vulnerabilityPassword are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt.EPSS 1.5%8.3CVE-2017-15654Asuswrt vulnerabilityHighly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allow gaining administrative rout…EPSS 2.1%7.5CVE-2018-20333Asuswrt information exposure vulnerabilityAn issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to t…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2018-6000), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.