CVE-2018-11340 describes an unrestricted file upload vulnerability in the importuser.cgi component of ASUSTOR AS6202T ADM 3.1.0.RFQ3. This flaw allows authenticated attackers with high privileges to upload arbitrary files, including malicious code, to the device's file system. The vulnerability carries a CVSS v3.0 score of 7.2 (HIGH), indicating a severe risk with high impact on confidentiality, integrity, and availability, requiring no user interaction. While the EPSS score is low, suggesting minimal current exploitation, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has not been added to CISA's KEV catalog. Community discussion and media coverage are also absent, indicating a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= adm_3.1.0.rfq3CPE matchmatch criteria | cpe:2.3:o:asustor:as6202t_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.