Vulnerabilities
Vulnerable Software
Asustor:  Security Vulnerabilities
An unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data via the POST parameter filename. This can be used to place attacker controlled code on the file system that can then be executed. Further, the filename parameter is vulnerable to path traversal and allows the attacker to place the file anywhere on the system.
CVSS Score
8.8
EPSS Score
0.019
Published
2018-05-22
An insecure direct object reference vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows the ability to reference the "download_sys_settings" action and then specify files arbitrarily throughout the system via the act parameter.
CVSS Score
4.3
EPSS Score
0.013
Published
2018-05-22


Contact Us

Shodan ® - All rights reserved