← Vulnerability feed

Vulnerability record · CVE-2018-8826 · published 20 April 2018

CVE-2018-8826: Asus rt-ac51u firmware improper input validation vulnerability

Asus · Rt Ac51u Firmware

ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N600 routers with firmware before 3.0.0.4.380.10446; RT-AC55U and RT-AC55UHP routers with firmware before 3.0.0.4.382.50276; RT-AC86U and RT-AC2900 routers with firmware before 3.0.0.4.384.20648; and possibly other RT-series routers allow remote attackers to execute arbitrary code via unspecified vectors.

9.8 CVSS 3.0 Critical EPSS 4.3% · top 9.3% CWE-20 · Improper input validation
9.8CVSS 3.0 base score, v2 7.5
4.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
13Affected product versions listed by NVD
28References
17 Jun 2026Last modified by NVD

Description

ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N600 routers with firmware before 3.0.0.4.380.10446; RT-AC55U and RT-AC55UHP routers with firmware before 3.0.0.4.382.50276; RT-AC86U and RT-AC2900 routers with firmware before 3.0.0.4.384.20648; and possibly other RT-series routers allow remote attackers to execute arbitrary code via unspecified vectors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.asus.com/Networking/RT-AC2900/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/Networking/RT-AC52U-B1/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/ca-en/Networking/RT-N600/HelpDesk_Download/ Vendor Advisory
https://www.asus.com/sg/Networking/RT-AC58U/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/Networking/RT-AC1200/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/Networking/RT-AC1750/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/Networking/RT-AC86U/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/Networking/RT-ACRH13/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/Networking/RTAC66U/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/Networking/RTN12_D1/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/Networking/RTN66W/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/supportonly/RT-AC51U/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/supportonly/RT-AC55U/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/supportonly/RT-AC55UHP/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/Networking/RT-AC2900/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/Networking/RT-AC52U-B1/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/ca-en/Networking/RT-N600/HelpDesk_Download/ Vendor Advisory
https://www.asus.com/sg/Networking/RT-AC58U/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/Networking/RT-AC1200/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/Networking/RT-AC1750/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/Networking/RT-AC86U/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/Networking/RT-ACRH13/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/Networking/RTAC66U/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/Networking/RTN12_D1/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/Networking/RTN66W/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/supportonly/RT-AC51U/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/supportonly/RT-AC55U/HelpDesk_BIOS/ Vendor Advisory
https://www.asus.com/us/supportonly/RT-AC55UHP/HelpDesk_BIOS/ Vendor Advisory

Track CVE-2018-8826 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-9285Asus rt-ac66u firmware os command injection vulnerabilityMain_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices before 3.0.0.4.38…EPSS 3.6%9.0CVE-2021-43702Asus zenwifi xd4s firmware cross-site scripting vulnerabilityASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if…EPSS 0.98%8.8CVE-2017-5891Asus rt-ac1750 firmware cross-site request forgery vulnerabilityASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 have Login Page CSRF and Save Settings CSRF.EPSS 0.48%7.5CVE-2021-3128Asus zenwifi ax \(xt8\) firmware vulnerabilityIn ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a …EPSS 2.2%7.5CVE-2017-5892Asus rt-ac1750 firmware information exposure vulnerabilityASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow JSONP Information Disclosure such as a network map.EPSS 1.2%6.5CVE-2017-8877Asus rt-ac1750 firmware information exposure vulnerabilityASUS RT-AC* and RT-N* devices with firmware through 3.0.0.4.380.7378 allow JSONP Information Disclosure such as the SSID.EPSS 0.86%6.5CVE-2017-8878Asus rt-ac1750 firmware information exposure vulnerabilityASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow remote authenticated users to discover the Wi-Fi password via WPS_info.xml.EPSS 1.0%6.1CVE-2021-46109Asus rt-ac52u b1 firmware cross-site scripting vulnerabilityInvalid input sanitizing leads to reflected Cross Site Scripting (XSS) in ASUS RT-AC52U_B1 3.0.0.4.380.10931 can lead to a user session hijack.EPSS 0.70%

Source: NIST National Vulnerability Database (record CVE-2018-8826), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.