CVE-2018-9077: Iomega and LenovoEMC NAS Web UI Vulnerabilities
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "" characters in the share : name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value c and iomega parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9077?
CVE-2018-9077 is classified as a high-severity vulnerability due to the risk of arbitrary command execution.
How do I fix CVE-2018-9077?
To fix CVE-2018-9077, you should upgrade to version 4.1.402.34663 or later for affected Lenovo and Iomega NAS devices.
What devices are affected by CVE-2018-9077?
CVE-2018-9077 affects certain Iomega and LenovoEMC NAS devices running firmware versions 4.1.402.34662 and earlier.
What type of attack can be carried out using CVE-2018-9077?
CVE-2018-9077 allows an attacker to execute arbitrary commands through crafted input in the share name parameter.
Is there any workaround for CVE-2018-9077 until I can update?
There are no known workarounds for CVE-2018-9077, so it is recommended to apply the firmware update as soon as possible.