CVE-2019-11689
Published
CVSS v3
8.1
HIGH
CVSS v2
9.3
HIGH
Affected
1
PROJECT
Description
An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl fail to properly validate server responses and pass unsanitized text to the system shell, resulting in code execution as root.