CVE-2018-14698: Drobo 5n2 Firmware

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the "username" URL parameter.

Affected products

  • Drobo 5n2 Firmware: version 4.0.5-13.28.96115 only

Published 2018-12-03. Last modified 2026-06-17.