Vulnerability Description
A cross site scripting (XSS) vulnerability on ASUS RT-AC58U 3.0.0.4.380_6516 devices allows remote attackers to inject arbitrary web script or HTML via Advanced_ASUSDDNS_Content.asp, Advanced_WSecurity_Content.asp, Advanced_Wireless_Content.asp, Logout.asp, Main_Login.asp, MobileQIS_Login.asp, QIS_wizard.htma, YandexDNS.asp, ajax_status.xml, apply.cgi, clients.asp, disk.asp, disk_utility.asp, or internet.asp.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Asus | Rt-Ac58U Firmware | 3.0.0.4.380.6516 |
| Asus | Rt-Ac58U | - |
Related Weaknesses (CWE)
References
- https://github.com/remix30303/AsusXSS/ExploitThird Party Advisory
- https://github.com/remix30303/AsusXSS/ExploitThird Party Advisory
FAQ
What is CVE-2018-18291?
CVE-2018-18291 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A cross site scripting (XSS) vulnerability on ASUS RT-AC58U 3.0.0.4.380_6516 devices allows remote attackers to inject arbitrary web script or HTML via Advanced_ASUSDDNS_Content.asp, Advanced_WSecurit...
How severe is CVE-2018-18291?
CVE-2018-18291 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-18291?
Check the references section above for vendor advisories and patch information. Affected products include: Asus Rt-Ac58U Firmware, Asus Rt-Ac58U.