Asus · Asus Webstorage · CVE-2022-26672
**Name of the Vulnerable Software and Affected Versions**
ASUS WebStorage (affected versions not specified)
**Description**
The issue concerns a hardcoded API Token in the APP source code of ASUS WebStorage. This allows an unauthenticated remote attacker to establish connections with the server and attempt to log in to general user accounts. If successful, the attacker can access, modify, or delete user account information.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.