CVE-2018-14701

CVE-2018-14701

Published · Updated

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 20%
exploitation probability
20%top 3% of all CVEs
observed exploitation
nono source reports it
System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL parameter.
Affected products
n/a · n/a