CVE-2018-11509
Description
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a webshell.
In plain language
AI Worth attentionIf you run an ASUSTOR Data Master with ADM 3.1.0.RFQ3, installed online-repository apps may share the same default root login (root:admin), letting an attacker log in and possibly add harmful code.
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin credentials for apps installed from the online repository, enabling an attacker to authenticate to the app component and upload a webshell (CWE-798).
What to do now
- Check whether your ASUSTOR Data Master is running ADM 3.1.0.RFQ3.
- Check whether you have installed any applications from ASUSTOR’s online repository (apps added via the online app/install feature).
- Immediately change the device/app default root credentials wherever applicable (do not leave root:admin in place).
- If you cannot confirm how those app credentials are handled on your device, disable/remove any online-repository apps that you don’t strictly need.
- Contact ASUSTOR support or your vendor and ask for the specific mitigation/patch for CVE-2018-11509, since no fixed version is listed in the available information.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-11509 and every CVE in our database. Create a free account — no credit card required.
Create Free Account