CVE-2018-14706
UnknownEPSS 17.11%
Last modified
CVE-2018-14706 is a vulnerability of currently unknown severity. System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the payload in a POST request.. EPSS estimates a 17.11% chance of exploitation in the next 30 days.
Description
System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the payload in a POST request.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Drobo | 5n2 Firmware | 4.0.5-13.28.96115 |
References
- https://blog.securityevaluators.com/call-me-a-doctor-new-vulnerabilities-in-drobo5n2-4f1d885df7fcExploit, Third Party Advisory
- https://blog.securityevaluators.com/call-me-a-doctor-new-vulnerabilities-in-drobo5n2-4f1d885df7fcExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-14706?
System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the payload in a POST request.
How severe is CVE-2018-14706?
Severity scoring for CVE-2018-14706 is pending analysis. The EPSS model estimates a 17.11% probability of exploitation in the next 30 days.
How do I fix CVE-2018-14706?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-14700Incorrect access control in the /mysql/api/logfile.php endpo…
- CVE-2018-14701System command injection in the /DroboAccess/delete_user end…
- CVE-2018-14702Incorrect access control in the /drobopix/api/drobo.php endp…
- CVE-2018-14703Incorrect access control in the /mysql/api/droboapp/data end…
- CVE-2018-14704Cross-site scripting in the MySQL API error page in Drobo 5N…
- CVE-2018-14705In Drobo 5N2 4.0.5, all optional applications lack any form …9.8
- CVE-2018-14707Directory traversal in the Drobo Pix web application on Drob…
- CVE-2018-14708An insecure transport protocol used by Drobo Dashboard API o…
- CVE-2018-14709Incorrect access control in the Dashboard API on Drobo 5N2 N…
- CVE-2018-1471Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-14710Cross-site scripting in appGet.cgi on ASUS RT-AC3200 version…
- CVE-2018-14711Missing cross-site request forgery protection in appGet.cgi …
Are you affected by CVE-2018-14706?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
