CVE-2018-11340: Malicious File Upload
An unrestricted file upload vulnerability in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data to a specified filename. This can be used to place attacker controlled code on the file system that is then executed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11340?
The severity of CVE-2018-11340 is critical, with a severity value of 7.2.
What software is affected by CVE-2018-11340?
ASUSTOR AS6202T ADM 3.1.0.RFQ3 firmware is affected by CVE-2018-11340.
How does the vulnerability in CVE-2018-11340 work?
The vulnerability in CVE-2018-11340 allows attackers to upload arbitrary files to a specified filename, potentially leading to the execution of attacker-controlled code.
Are there any publicly available exploits for CVE-2018-11340?
Yes, there are publicly available exploits for CVE-2018-11340. Please refer to the provided references for more information.
How can I mitigate the vulnerability in CVE-2018-11340?
To mitigate the vulnerability in CVE-2018-11340, it is recommended to update ASUSTOR AS6202T ADM firmware to a version that addresses the issue.