CVE-2018-11509 describes a critical vulnerability in ASUSTOR ADM 3.1.0.RFQ3 where applications installed from the online repository use the same default root:admin credentials as the NAS itself. This allows unauthenticated attackers to easily log in and upload webshells, leading to complete compromise of the system. With a CVSS score of 9.8 (Critical) and an attack vector of Network, this vulnerability is easily exploitable with low complexity and no user interaction. While not listed in CISA KEV, public exploit code exists on ExploitDB, and it has garnered significant community discussion, indicating a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1.0CPE matchmatch criteria | cpe:2.3:a:asustor:asustor_data_master:3.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.