STAR Labs disclosed two vulnerabilities in ASUSWRT version 3.0.0.4.384.20308 that exposed ASUS routers to remote attack. The more severe issue, tracked as CVE-2018-20334, was a command injection flaw in the web interface endpoint start_apply.htm, where crafted POST data supplied through the fb_email parameter could be used to execute commands on the device. A proof of concept showed an attacker starting telnetd, indicating the bug could enable full router compromise.
A second flaw, CVE-2018-20335, allowed an unauthenticated attacker to deny service by sending a crafted HTTP request with a malicious asus_token cookie, causing the router's httpd process to hang while handling the Cookie header in handle_request. ASUS was notified of both issues, acknowledged them, and released firmware updates to remediate the vulnerabilities; the vendor said the update also addressed CVE-2018-20336.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
ASUS published updated firmware to remediate the disclosed ASUSWRT vulnerabilities. The CVE-2018-20334 advisory states the fix was released on 2019-03-29, and the vendor confirmed the update also addressed CVE-2018-20336; CVE-2018-20335 was also described as patched via firmware update.
ASUS acknowledged the reported vulnerabilities after receiving STAR Labs' disclosure. The acknowledgment is explicitly noted for both CVE-2018-20334 and CVE-2018-20335.
STAR Labs disclosed multiple ASUSWRT flaws to ASUS, including CVE-2018-20334, a command injection issue in /start_apply.htm, and CVE-2018-20335, a denial-of-service flaw affecting the router's HTTP service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.