CVE-2018-11344

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
22/05/2018
Last modified:
21/03/2019

Description

A path traversal vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily specify a file on the system to download via the file1 parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:asustor:as6202t_firmware:*:*:*:*:*:*:*:* adm_3.1.0.rfq3 (including)
cpe:2.3:h:asustor:as6202t:-:*:*:*:*:*:*:*