CVE-2018-11509: Critical severity asustor data master vulnerability
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a webshell.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-11509.
What is the severity of CVE-2018-11509?
The severity of CVE-2018-11509 is critical, with a severity value of 9.8.
What is the affected software for CVE-2018-11509?
The affected software for CVE-2018-11509 is ASUSTOR ADM version 3.1.0.RFQ3.
What is the risk of CVE-2018-11509?
CVE-2018-11509 allows an attacker to login and upload a webshell, presenting a high risk of unauthorized access and potential control of the affected system.
How can I fix CVE-2018-11509?
To fix CVE-2018-11509, it is recommended to update ASUSTOR ADM to a version that does not use the same default root:admin username and password for applications installed from the online repository.