CVE-2019-11689: OS Command Injection
An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl fail to properly validate server responses and pass unsanitized text to the system shell, resulting in code execution as root.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11689?
CVE-2019-11689 is a vulnerability in ASUSTOR exFAT Driver through 1.0.0.r20 that allows code execution as root.
What is the severity of CVE-2019-11689?
The severity of CVE-2019-11689 is critical with a CVSS score of 8.1.
Which software versions are affected by CVE-2019-11689?
Versions 1.0.0-r14, 1.0.0-r15, and 1.0.0-r20 of ASUSTOR exFAT Driver are affected by CVE-2019-11689.
How can I fix CVE-2019-11689?
To fix CVE-2019-11689, update ASUSTOR exFAT Driver to a version that is not affected.
What is the CWE classification for CVE-2019-11689?
CVE-2019-11689 is classified under CWE-78, which is Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').