Multiple Critical Vulnerabilities in ASUSTOR ADM 3.1.0.RFQ3 and all previous builds
The Asustor NAS appliance on ADM 3.1.0 and before suffer from multiple critical vulnerabilities. The vulnerabilities were submitted to Asustor in January and February 2018. The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by embedding OS commands in the 'script' parameter. The application fails to santitize user input after the cgi file executes a call to a local shell script. Exploitation of this vulnerability allows an attacker execution of arbitrary commands on the host operating system, as the root user, remotely and unauthenticated. The tree list functionality in the photo gallery application of the ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from multiple blind SQL injection vulnerabilities. The application fails to santitize user input after the cgi file executes a call to a local shell script. Exploitation of this vulnerability allows an attacker to extract sensitive information from the database, such as usernames and passwords, remotely and unauthenticated.