CVE-2018-11346: Asustor AS6202T Firmware

Medium severity, CVSS 4.3. EPSS: 1.3% chance of exploitation in the next 30 days.

An insecure direct object reference vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows the ability to reference the "download_sys_settings" action and then specify files arbitrarily throughout the system via the act parameter.

Affected products

  • Asustor AS6202T Firmware: up to and including adm_3.1.0.rfq3

Published 2018-05-22. Last modified 2026-06-17.