CVE-2018-18287: ASUS Rt-AC58U Firmware

Medium severity, CVSS 5.3. EPSS: 1.7% chance of exploitation in the next 30 days.

On ASUS RT-AC58U 3.0.0.4.380_6516 devices, remote attackers can discover hostnames and IP addresses by reading dhcpLeaseInfo data in the HTML source code of the Main_Login.asp page.

Affected products

  • ASUS Rt-AC58U Firmware: version 3.0.0.4.380.6516 only

Published 2018-10-14. Last modified 2026-06-17.