Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The ORICO NAS CD3510 (version V1.9.12 and below) contains an Incorrect Symlink Follow vulnerability that could be exploited by attackers to leak or tamper with the internal file system. Attackers can format a USB drive to ext4, create a symbolic link to its root directory, insert the drive into the NAS device's slot, then access the USB drive's symlink directory mounted on the NAS to obtain all files within the NAS system and tamper with those files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ORICO NAS CD3510 安全漏洞
Vulnerability Description
ORICO NAS CD3510是ORICO公司的一个个人存储设备。 ORICO NAS CD3510 V1.9.12及之前版本存在安全漏洞,该漏洞源于符号链接跟随不正确,可能导致泄露或篡改内部文件系统。
CVSS Information
N/A
Vulnerability Type
N/A