CVE-2018-18320: Asuswrt-Merlin Project Rt-AC1900 Firmware

Critical severity, CVSS 9.8. EPSS: 5.2% chance of exploitation in the next 30 days.

An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because exec.php has a popen call. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution

Affected products

Published 2018-10-15. Last modified 2026-06-17.