CVE-2018-5999: ASUS Asuswrt

Critical severity, CVSS 9.8. EPSS: 87.3% chance of exploitation in the next 30 days.

An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests continues even if authentication fails.

Affected products

  • ASUS Asuswrt: before 3.0.0.4.384_10007 (fixed in 3.0.0.4.384_10007)

Published 2018-01-22. Last modified 2026-06-17.