CVE-2018-11346: Medium severity ASUSTOR As6202t Firmware vulnerability
An insecure direct object reference vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows the ability to reference the "downloadsyssettings" action and then specify files arbitrarily throughout the system via the act parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11346?
CVE-2018-11346 is an insecure direct object reference vulnerability in ASUSTOR AS6202T ADM 3.1.0.RFQ3.
How does CVE-2018-11346 work?
CVE-2018-11346 allows an attacker to reference the "download_sys_settings" action and specify files arbitrarily throughout the system using the act parameter.
What is the severity of CVE-2018-11346?
The severity of CVE-2018-11346 is medium with a CVSS score of 4.3.
How can I fix CVE-2018-11346?
To fix CVE-2018-11346, update ASUSTOR AS6202T ADM to version 3.1.0.RFQ4 or later.
Where can I find more information about CVE-2018-11346?
You can find more information about CVE-2018-11346 on the following references: [Reference 1](http://seclists.org/fulldisclosure/2018/May/2), [Reference 2](https://github.com/mefulton/asustorexploit), [Reference 3](https://www.purehacking.com/blog/matthew-fulton/back-to-the-future-asustor-web-exploitation).