CVE-2018-9074: Lenovo Lenovoemc Firmware

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the device's operating system as the root user.

Affected products

  • Lenovo Lenovoemc Firmware: up to and including 4.1.402.34662

Published 2018-09-28. Last modified 2026-06-17.