Vulnerabilities (CVE)

Filtered by vendor Asustor Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-11509 1 Asustor 1 Asustor Data Master 2019-10-03 7.5 HIGH 9.8 CRITICAL
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a webshell.
CVE-2018-11510 1 Asustor 1 Adm 2019-10-03 5.0 MEDIUM 9.8 CRITICAL
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by embedding OS commands in the 'script' parameter.
CVE-2018-12313 1 Asustor 2 As602t, Data Master 2019-10-03 10.0 HIGH 9.8 CRITICAL
OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity" URL parameter.
CVE-2018-11511 1 Asustor 1 Asustor Data Master 2018-10-19 7.5 HIGH 9.8 CRITICAL
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI.