CVE-2018-9074: Lenovo Lenovoemc Firmware
Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the device's operating system as the root user.
Affected products
- Lenovo Lenovoemc Firmware: up to and including 4.1.402.34662
Published 2018-09-28. Last modified 2026-06-17.