Loading
Stack-based buffer overflow in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to execute arbitrary code by providing a long string to the blocking.asp page via a GET or POST request. Vulnerable parameters are flag, mac, and cat_id.
Use CWE-787, Asus vendor hub and Rt-Ac66u Firmware product page to widen CVE-2018-8879 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2013-6343, CVE-2013-4937 and CVE-2013-4656 for nearby disclosures in the same product family.