CVE-2018-9074

Publication date

2018-09-28 20:00:00

Family

lenovo

State

PUBLISHED

Description

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the devices operating system as the root user.