Vulnerabilities (CVE)

Filtered by vendor Asustor Subscribe
Filtered by product Exfat Driver
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-11689 1 Asustor 1 Exfat Driver 2023-12-10 9.3 HIGH 8.1 HIGH
An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl fail to properly validate server responses and pass unsanitized text to the system shell, resulting in code execution as root.
CVE-2019-11688 1 Asustor 1 Exfat Driver 2023-12-10 8.8 HIGH 7.4 HIGH
An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl accept any certificate for asustornasapi.asustor.com. In other words, there is Missing SSL Certificate Validation.