PT-2018-10625 · Asustor · Asustor Adm
Kyle Lovett
+1
·
Published
2018-08-16
·
Updated
2019-10-03
·
CVE-2018-11509
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ASUSTOR ADM version 3.1.0.RFQ3
Description
The issue allows an attacker to login using the default root:admin username and password, which is the same as the one used for the NAS itself for applications installed from the online repository. This may enable an attacker to upload a webshell.
Recommendations
For ASUSTOR ADM version 3.1.0.RFQ3, change the default root:admin username and password to unique and strong credentials to prevent unauthorized access. Consider restricting access to the administrative interface until the issue is resolved.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asustor Adm