CVE-2018-11340

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
22/05/2018
Last modified:
21/03/2019

Description

An unrestricted file upload vulnerability in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data to a specified filename. This can be used to place attacker controlled code on the file system that is then executed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:asustor:as6202t_firmware:*:*:*:*:*:*:*:* adm_3.1.0.rfq3 (including)
cpe:2.3:h:asustor:as6202t:-:*:*:*:*:*:*:*