Information Disclosure Vulnerability in ASUSWRT by ASUS
CVE-2018-20333
7.5HIGH
What is CVE-2018-20333?
An information disclosure vulnerability has been identified in ASUSWRT, allowing unauthenticated users to access sensitive information through the /update_applist.asp endpoint. This flaw enables malicious actors to determine if a USB device is connected to the router and to enumerate installed applications, potentially compromising the security and privacy of the device and its users.