← Vulnerability feed

Vulnerability record · CVE-2018-8879 · published 21 November 2019

CVE-2018-8879: Asus rt-ac66u firmware out-of-bounds write vulnerability

Asus · Rt Ac66u Firmware

Stack-based buffer overflow in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to execute arbitrary code by providing a long string to the blocking.asp page via a GET or POST request. Vulnerable parameters are flag, mac, and cat_id.

9.8 CVSS 3.1 Critical EPSS 17% · top 3.0% CWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score, v2 7.5
17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to execute arbitrary code by providing a long string to the blocking.asp page via a GET or POST request. Vulnerable parameters are flag, mac, and cat_id.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-8879 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-6343Asus tm-ac1900 firmware memory buffer overflow vulnerabilityMultiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow remote attackers to execute …EPSS 7.8%10.0CVE-2013-4937Asus rt-ac66u firmware vulnerabilityMultiple unspecified vulnerabilities in the AiCloud feature on the ASUS RT-AC66U, RT-N66U, RT-N65U, RT-N14U, RT-N16, RT-N56U, and DSL-N55U with firmw…EPSS 1.9%9.8CVE-2013-4656Asus rt-ac66u firmware path traversal vulnerabilitySymlink Traversal vulnerability in ASUS RT-AC66U and RT-N56U due to misconfiguration in the SMB service.EPSS 2.2%9.8CVE-2018-8826Asus rt-ac51u firmware improper input validation vulnerabilityASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N…EPSS 4.3%9.8CVE-2018-9285Asus rt-ac66u firmware os command injection vulnerabilityMain_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices before 3.0.0.4.38…EPSS 3.6%9.8CVE-2013-4659Asus rt-ac66u firmware memory buffer overflow vulnerabilityBuffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on rout…EPSS 14%9.0CVE-2021-43702Asus zenwifi xd4s firmware cross-site scripting vulnerabilityASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if…EPSS 0.98%8.8CVE-2013-3093Asus rt-n56u firmware cross-site request forgery vulnerabilityASUS RT-N56U devices allow CSRF.EPSS 0.74%

Source: NIST National Vulnerability Database (record CVE-2018-8879), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.