cbcvebase.
CVE-2018-11509
published 2018-08-16

CVE-2018-11509: ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online…

PriorityP269critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
12.57%
95.7th percentile
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a webshell.

Affected

1 ranges
VendorProductVersion rangeFixed in
asustorasustor_data_master

Detection & IOCsextracted from sources · hover to see the quote

urlhttp://<host>/phpmyadmin/
urlhttp://<host>:8001/portal/
path/volume1/Web/
  • Alert on webshell uploads to /volume1/Web/ on ASUSTOR NAS devices, which is the publicly accessible web root used by add-on applications.
  • Detect logins to the NAS admin portal on port 8001 using the default account nvradmin, which provides a foothold even without full admin permissions.
  • ·CVE-2018-11509 affects ASUSTOR ADM 3.1.0.RFQ3 and all previous builds. The default credentials vulnerability stems from add-on applications (phpmyadmin, virtualbox, owncloud, photo-gallery, etc.) never prompting users to change default passwords during NAS initialization.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.