CVE-2018-8878 is an information disclosure vulnerability affecting Asuswrt-Merlin firmware older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for ASUS devices. This flaw allows remote attackers to obtain internal network device hostnames and MAC addresses by accessing the custom_id variable on the blocking.asp page. Rated as Medium severity (CVSS 5.3), it requires no user interaction or authentication, but only leads to a low impact on confidentiality. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or ExploitDB, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 384.4CPE matchmatch criteria | cpe:2.3:o:asuswrt-merlin:asuswrt-merlin:*:*:*:*:*:*:*:* | ||
< 3.0.0.4.382.50470CPE matchmatch criteria | cpe:2.3:o:asus:asus_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.