CVE-2018-9075: Iomega and LenovoEMC NAS Web UI Vulnerabilities
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a command injection payload using backtick "" characters in the client:password parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value c and iomega parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9075?
CVE-2018-9075 has a severity rating of medium due to the potential for command injection.
How do I fix CVE-2018-9075?
To mitigate CVE-2018-9075, upgrade your Lenovo or LenovoEMC NAS devices to firmware version 4.1.402.34663 or later.
What devices are affected by CVE-2018-9075?
CVE-2018-9075 affects Lenovo and LenovoEMC NAS devices running firmware versions 4.1.402.34662 and earlier.
What can an attacker achieve with CVE-2018-9075?
An attacker can execute arbitrary commands on affected devices by leveraging command injection through crafted payloads.
Is CVE-2018-9075 still exploitable?
CVE-2018-9075 is only exploitable on devices that have not been updated to firmware versions patched against this vulnerability.