S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 6, 2025

CVE-2018-11511 Scanner

CVE-2018-11511 Scanner - SQL Injection vulnerability in ASUSTOR ADM

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.5k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-11511
9.8
CVSS

The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

ASUSTOR ADM is software used predominantly for managing NAS devices, catering to both private and enterprise storage solutions. This network-attached storage system software allows users to back up, sync, and share data from centralized data storage remotely and securely. ASUSTOR ADM is utilized by various sectors for efficient data management, ensuring data's security and accessibility. Featuring a user-friendly interface, it is ideal for those who need a comprehensive and manageable storage solution. Many enterprises leverage ASUSTOR ADM for its great balance between functionality, cost, and user control. The flexibility of its setup options adapts well to growing storage needs within an organization.

SQL Injection is a web security vulnerability that allows an attacker to interfere with the queries that an application makes to its database. It generally allows for unauthorized viewing of data, which could lead to further attacks on the system. The vulnerability detected in ASUSTOR ADM allows attackers to execute arbitrary SQL commands in the database. It can be exploited through the manipulation of the 'album_id' parameter in the endpoint '/photo-gallery/api/album/tree_lists/'. Successful compromise could lead to considerable information exposure or even system takeover. Such vulnerabilities are critical due to their potential impact and exploitability.

Technical details of the vulnerability involve specifically crafted payloads submitted to ASUSTOR ADM's endpoint. Attackers can manipulate the 'album_id' parameter to inject harmful SQL code using the SQL Sleep function or logical operations for verification. If a vulnerable parameter accepts unsanitized input, attackers can alter SQL queries executed by the backend database server. The check evaluates the delay in response time and verification of error messages or rich expected outputs post-injection. This kind of parameter tampering illustrates a typical blind SQL injection vector. Strategic injection points in ASUSTOR ADM could further empower attackers to execute queries on its database backend without prior authorization.

Possible effects when this vulnerability is exploited include unauthorized access to sensitive data, such as user credentials or financial information. Once the database structure is accessed, it is possible to extract data or even make unauthorized alterations to it. Further malicious activity may involve corrupting data, installing a backdoor, or using the gained control to its full advantage in a cyber-espionage scheme. Such SQL injections could also be stepping stones to command execution depending on the database server's configuration and privileges. Data breaches due to SQL injection can lead to long-term reputational harm and financial losses for the affected organization.

REFERENCES

Solution Advice
  • Secure the affected endpoint with rigorous input validation and parameterized queries to prevent SQL injection.
  • Update ASUSTOR ADM to a patched version once available, ensuring that the vulnerability is mitigated.
  • Regularly test codes against security vulnerabilities and apply security patches promptly.
  • Employ security mechanisms such as Web Application Firewalls to help identify and block SQL injection attempts.
  • Conduct routine security audits and reviews on database query interactions and management.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-11511 Scanner - SQL Injection vulnerability in ASUSTOR ADM | S4E