Remote Information Disclosure Vulnerability in ASUS Routers
CVE-2018-18287
5.3MEDIUM
What is CVE-2018-18287?
The ASUS RT-AC58U device, running version 3.0.0.4.380_6516, is susceptible to a vulnerability that allows remote attackers to access sensitive information. By exploiting this weakness, attackers can extract hostnames and IP addresses from the dhcpLeaseInfo data, which is exposed in the HTML source code of the Main_Login.asp page. This can lead to unauthorized network reconnaissance and potential further attacks.