CVE-2018-11510: Asustor Adm

Critical severity, CVSS 9.8. EPSS: 44.3% chance of exploitation in the next 30 days.

The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by embedding OS commands in the 'script' parameter.

Affected products

  • Asustor Adm: up to and including 3.1.2.rhg1

Published 2018-06-28. Last modified 2026-06-17.