CVE-2018-12312: Command Injection
OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "secretkey" URL parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-12312?
CVE-2018-12312 is a vulnerability in ASUSTOR ADM version 3.1.1 that allows attackers to execute system commands as root via the "secret_key" URL parameter.
What is the severity of CVE-2018-12312?
The severity of CVE-2018-12312 is critical with a CVSS score of 8.8.
How does CVE-2018-12312 affect ASUSTOR ADM version 3.1.1?
CVE-2018-12312 allows attackers to execute system commands as root in ASUSTOR ADM version 3.1.1 through the "secret_key" URL parameter.
How can I fix CVE-2018-12312?
To fix CVE-2018-12312, update ASUSTOR ADM to a version that has a patch for this vulnerability.
Are there any references for CVE-2018-12312?
Yes, you can find more information about CVE-2018-12312 at this link: https://blog.securityevaluators.com/over-a-dozen-vulnerabilities-discovered-in-asustor-as-602t-8dd5832a82cc