CVE-2018-8879: ASUS Rt-AC66U Firmware
Critical severity, CVSS 9.8. EPSS: 17.2% chance of exploitation in the next 30 days.
Stack-based buffer overflow in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to execute arbitrary code by providing a long string to the blocking.asp page via a GET or POST request. Vulnerable parameters are flag, mac, and cat_id.
Affected products
- ASUS Rt-AC66U Firmware: before 3.0.0.4.382.50470 (fixed in 3.0.0.4.382.50470)
Published 2019-11-21. Last modified 2026-06-17.