CVE-2018-11510: OS Command Injection
Published Jun 28, 2018
·Updated
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecatejs.cgi file by embedding OS commands in the 'script' parameter.
Affected Software
1 affected component
ASUSTOR ADM<=3.1.2.rhg1
Event History
Jun 28, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-11510?
CVE-2018-11510 is an unauthenticated remote code execution vulnerability in the ASUSTOR ADM 3.1.0.RFQ3 NAS portal.
2
How severe is CVE-2018-11510?
CVE-2018-11510 has a severity rating of 9.8 out of 10.
3
What software is affected by CVE-2018-11510?
The ASUSTOR ADM software version up to 3.1.2.rhg1 is affected by CVE-2018-11510.
4
How does CVE-2018-11510 work?
CVE-2018-11510 allows an attacker to execute remote code by embedding OS commands in the 'script' parameter of the portal/apis/aggrecate_js.cgi file.
5
Is there a fix for CVE-2018-11510?
Yes, upgrading to a version of ASUSTOR ADM that is not affected by the vulnerability is the recommended fix for CVE-2018-11510.