CVE-2019-11689

HIGH

ASUSTOR exFAT Driver <1.0.0.r20 - Code Injection

Title source: llm
STIX 2.1

Description

An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl fail to properly validate server responses and pass unsanitized text to the system shell, resulting in code execution as root.

References (2)

Core 2
Core References

Scores

CVSS v3 8.1
EPSS 0.0316
EPSS Percentile 86.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
asustor/exfat_driver 1.0.0 r14 (3 CPE variants)
Published Mar 18, 2020
Tracked Since Feb 18, 2026