CVE-2018-20333: ASUS Asuswrt
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to the router and if there are apps installed on the router.
Affected products
- ASUS Asuswrt: version 3.0.0.4.384.20308 only
Published 2020-03-20. Last modified 2026-06-17.