CVE-2018-8878: ASUS Firmware
Medium severity, CVSS 5.3. EPSS: 1.5% chance of exploitation in the next 30 days.
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page.
Affected products
- ASUS ASUS Firmware: before 3.0.0.4.382.50470 (fixed in 3.0.0.4.382.50470)
- Asuswrt-Merlin Asuswrt-Merlin: before 384.4 (fixed in 384.4)
Published 2020-02-27. Last modified 2026-06-17.