LiveActive security incident?Get immediate response
CVE Record

CVE-2018-8826: ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4...

ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N600 routers with firmware before 3.0.0.4.380.10446; RT-AC55U and RT-AC55UHP routers with firmware before 3.0.0.4.382.50276; RT-AC86U and RT-AC2900 routers with firmware before 3.0.0.4.384.20648; and possibly other RT-series routers allow remote attackers to execute arbitrary code via unspecified vectors.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

This CVE concerns several ASUS RT-series routers where old firmware may let a remote attacker run arbitrary code. For executives, the risk is loss of control over edge network equipment, traffic exposure, or foothold creation. The public record does not provide CVSS, CWE, or attack vector detail.

Executive priority

Prioritize remediation where affected routers protect business networks or remote offices. Remote code execution on edge devices can become a serious operational risk, but the public evidence lacks severity scoring and exploitation confirmation. Handle as high priority for known affected, outdated devices.

Technical view

The CVE record lists remote arbitrary code execution in multiple ASUS RT-series router models running firmware below specified fixed builds. Affected models include RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, RT-N12 D1, RT-AC52U B1, RT-AC1200, RT-N600, RT-AC55U, RT-AC55UHP, RT-AC86U, RT-AC2900, and possibly others.

Likely exposure

Exposure is most likely where listed ASUS routers remain deployed with firmware older than the CVE record’s fixed versions. Small offices, branch sites, home offices, and unmanaged consumer routers are plausible exposure points. Evidence for additional RT-series models is incomplete because the record says only “possibly other” routers.

Exploitation context

The supplied sources state remote arbitrary code execution through unspecified vectors. They do not cite public exploit code, observed exploitation, or CISA KEV listing; KEV is false in the bundle. Treat exploitation status as unconfirmed, not inactive.

Researcher notes

The core limitation is attribution depth: vectors, CWE, CVSS, and exploit conditions are not specified in the provided record. Analysis should stay model-and-firmware focused. Avoid extrapolating to non-listed ASUS products except noting the record’s “possibly other RT-series routers” language.

Mitigation direction

  • Inventory ASUS RT-series routers and map exact model and firmware version.
  • Upgrade affected routers to ASUS firmware at or above the listed fixed build.
  • Check ASUS support pages for current model-specific firmware guidance.
  • Restrict router administration exposure to trusted management networks.
  • Replace unsupported devices if fixed firmware is unavailable.

Validation and detection

  • Confirm each router model against the CVE affected model list.
  • Record current firmware and compare it with the relevant fixed version threshold.
  • Review router management exposure from internal and external network perspectives.
  • Check ASUS support pages for the latest firmware available per model.
  • Document exceptions where models are only possibly affected.
Prepared
Confidence
medium
Sources
12

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2018-8826 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
15Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.