CVE-2018-18319: Asuswrt-Merlin Project Rt-AC1900 Firmware

Critical severity, CVSS 9.8. EPSS: 5.4% chance of exploitation in the next 30 days.

An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has an eval call, as demonstrated by the /6/api.php?function=command&class=remote&Cc='ls' URI. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution

Affected products

Published 2018-10-15. Last modified 2026-06-17.