CVE-2018-11510
CRITICAL EXPLOITED IN THE WILDAsustor Adm < 3.1.2.rhg1 - OS Command Injection
Title source: ruleDescription
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by embedding OS commands in the 'script' parameter.
Exploits (3)
exploitdb
WORKING POC
by Matthew Fulton · pythonwebappshardware
https://www.exploit-db.com/exploits/45212
References (5)
Scores
CVSS v3
9.8
EPSS
0.8936
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2019-02-21
InTheWild.io
2019-12-13
CWE
CWE-78
Status
published
Products (1)
asustor/adm
< 3.1.2.rhg1
Published
Jun 28, 2018
Tracked Since
Feb 18, 2026