CVE-2019-11689

Published
View on NVD ↗
CVSS v3
8.1
HIGH
CVSS v2
9.3
HIGH
Affected
1
PROJECT

Description

An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl fail to properly validate server responses and pass unsanitized text to the system shell, resulting in code execution as root.