CVE-2018-11510
CRITICAL EXPLOITED IN THE WILDASUSTOR ADM < 3.1.2.rhg1 - Unauthenticated Remote Code Execution via script Parameter
Title source: llmExploitation Summary
CVE-2018-11510 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 3 public exploits from researchers including Matthew Fulton, Kyle Lovett, mefulton.
AI-analyzed exploit summary This exploit leverages an unauthenticated OS command injection vulnerability in Asustor ADM 3.1.2.RHG1 and below to execute arbitrary commands, resulting in a root shell. It uses a crafted URL to inject a Python reverse shell payload via the `aggrecate_js.cgi` endpoint.
Description
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by embedding OS commands in the 'script' parameter.
Exploits (3)
This exploit leverages an unauthenticated OS command injection vulnerability in Asustor ADM 3.1.2.RHG1 and below to execute arbitrary commands, resulting in a root shell. It uses a crafted URL to inject a Python reverse shell payload via the `aggrecate_js.cgi` endpoint.
The provided text is a detailed writeup describing multiple vulnerabilities in ASUSTOR ADM 3.1.0.RFQ3, including CVE-2018-11511, a blind SQL injection in the photo gallery application. It includes PoC examples using sqlmap for exploitation but does not contain executable exploit code.
This repository contains a working proof-of-concept exploit for CVE-2018-11510, an unauthenticated command injection vulnerability in Asustor ADM 3.1.2.RHG1. The exploit includes a Metasploit module and a Python script to achieve remote code execution and obtain a root shell.
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H