Information Exposure Affecting rmerl/asuswrt-merlin package, versions [,384.4)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.12% (48th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-RMERLASUSWRTMERLIN-2369599
  • published26 Jan 2022
  • disclosed27 Feb 2020
  • creditUnknown

Introduced: 27 Feb 2020

CVE-2018-8878  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade rmerl/asuswrt-merlin to version 384.4 or higher.

Overview

Affected versions of this package are vulnerable to Information Exposure. Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page.

References

CVSS Base Scores

version 3.1