Main_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices before 3.0.0.4.384_10007; RT-N18U devices before 3.0.0.4.382.39935; RT-AC87U and RT-AC3200 devices before 3.0.0.4.382.50010; and RT-AC5300 devices before 3.0.0.4.384.20287 allows OS command injection via the pingCNT and destIP fields of the SystemCmd variable.
Conclusion & alert: CVE-2018-9285 is rated High Risk (70.8/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 3.61%). Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 2.80% | 3.61% | +0.81% |
| 2 | 2025-11-21 | 10.24% | 2.80% | -7.43% |
| 3 | 2025-11-18 | — | 10.24% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.0 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 10.0 | 2.0 | HIGH |
|
10.0 | 10.0 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| asus | rt-ac66u_firmware | < 3.0.0.4.384.10007 | cpe:2.3:o:asus:rt-ac66u_firmware:*:*:*:*:*:*:*:* |
| asus | rt-ac68u_firmware | < 3.0.0.4.384.10007 | cpe:2.3:o:asus:rt-ac68u_firmware:*:*:*:*:*:*:*:* |
| asus | rt-ac86u_firmware | < 3.0.0.4.384.10007 | cpe:2.3:o:asus:rt-ac86u_firmware:*:*:*:*:*:*:*:* |
| asus | rt-ac88u_firmware | < 3.0.0.4.384.10007 | cpe:2.3:o:asus:rt-ac88u_firmware:*:*:*:*:*:*:*:* |
| asus | rt-ac1900_firmware | < 3.0.0.4.384.10007 | cpe:2.3:o:asus:rt-ac1900_firmware:*:*:*:*:*:*:*:* |
| asus | rt-ac2900_firmware | < 3.0.0.4.384.10007 | cpe:2.3:o:asus:rt-ac2900_firmware:*:*:*:*:*:*:*:* |
| asus | rt-ac3100_firmware | < 3.0.0.4.384.10007 | cpe:2.3:o:asus:rt-ac3100_firmware:*:*:*:*:*:*:*:* |
| asus | rt-n18u_firmware | < 3.0.0.4.382.39935 | cpe:2.3:o:asus:rt-n18u_firmware:*:*:*:*:*:*:*:* |
| asus | rt-ac87u_firmware | < 3.0.0.4.382.50010 | cpe:2.3:o:asus:rt-ac87u_firmware:*:*:*:*:*:*:*:* |
| asus | rt-ac3200_firmware | < 3.0.0.4.382.50010 | cpe:2.3:o:asus:rt-ac3200_firmware:*:*:*:*:*:*:*:* |
| asus | rt-ac5300_firmware | < 3.0.0.4.384.20287 | cpe:2.3:o:asus:rt-ac5300_firmware:*:*:*:*:*:*:*:* |