CVE-2018-18320: Asuswrt-Merlin Project Rt-AC1900 Firmware
Critical severity, CVSS 9.8. EPSS: 5.2% chance of exploitation in the next 30 days.
An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because exec.php has a popen call. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution
Affected products
- Asuswrt-Merlin Project Rt-AC1900 Firmware: up to and including 380.70
- Asuswrt-Merlin Project Rt-AC2900 Firmware: up to and including 380.70
- Asuswrt-Merlin Project Rt-AC3100 Firmware: up to and including 380.70
- Asuswrt-Merlin Project Rt-AC3200 Firmware: up to and including 380.70
- Asuswrt-Merlin Project Rt-AC5300 Firmware: up to and including 380.70
- Asuswrt-Merlin Project Rt-AC56U Firmware: up to and including 380.70
- Asuswrt-Merlin Project Rt-AC66U b1 Firmware: up to and including 380.70
- Asuswrt-Merlin Project Rt-AC68P Firmware: up to and including 380.70
- Asuswrt-Merlin Project Rt-AC68U Firmware: up to and including 380.70
- Asuswrt-Merlin Project Rt-AC68UF Firmware: up to and including 380.70
- Asuswrt-Merlin Project Rt-AC86U Firmware: up to and including 380.70
- Asuswrt-Merlin Project Rt-AC87 Firmware: up to and including 380.70
- Asuswrt-Merlin Project Rt-AC88U Firmware: up to and including 380.70
- Asuswrt-Merlin Project Rt AC1900P Firmware: up to and including 380.70
Published 2018-10-15. Last modified 2026-06-17.