CVE-2018-8877: ASUS Firmware

Medium severity, CVSS 5.3. EPSS: 1.5% chance of exploitation in the next 30 days.

Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network IP address ranges by reading the new_lan_ip variable on the error_page.htm page.

Affected products

  • ASUS ASUS Firmware: before 3.0.0.4.382.50470 (fixed in 3.0.0.4.382.50470)
  • Asuswrt-Merlin Asuswrt-Merlin: before 384.4 (fixed in 384.4)

Published 2020-02-27. Last modified 2026-06-17.