PT-2018-10625 · Asustor · Asustor Adm

Kyle Lovett

+1

·

Published

2018-08-16

·

Updated

2019-10-03

·

CVE-2018-11509

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ASUSTOR ADM version 3.1.0.RFQ3
Description The issue allows an attacker to login using the default root:admin username and password, which is the same as the one used for the NAS itself for applications installed from the online repository. This may enable an attacker to upload a webshell.
Recommendations For ASUSTOR ADM version 3.1.0.RFQ3, change the default root:admin username and password to unique and strong credentials to prevent unauthorized access. Consider restricting access to the administrative interface until the issue is resolved.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11509

Affected Products

Asustor Adm