ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin...
Critical severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Description
Published by the National Vulnerability Database
Aug 16, 2018
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 2, 2023
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a webshell.
References