CVE-2018-18471
Description
/api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability that can be chained with an SSRF bug to gain remote command execution as root. It can be triggered by anyone who knows the IP address of the affected device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An XXE vulnerability in Axentra /api/2.0/rest/aggregator/xml, chained with SSRF, allows unauthenticated remote attackers to execute arbitrary commands as root on several branded NAS devices.
Vulnerability
The /api/2.0/rest/aggregator/xml endpoint in Axentra firmware, shipped on NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud NAS devices, contains an XML External Entity (XXE) vulnerability [1]. The handler does not disable external entity processing, allowing an attacker to embed malicious XML entities in the request body. Affected firmware versions were distributed with the hardware at the time of publication; no specific version numbers are disclosed in the references, but the flaw exists in the stock firmware [1].
Exploitation
An attacker who knows the device's IP address can send a crafted HTTP POST request to /api/2.0/rest/aggregator/xml containing an XML payload with an external entity that references a local resource or an attacker-controlled URL [1]. The XXE can be chained with a Server-Side Request Forgery (SSRF) vulnerability in the same endpoint [1]. No authentication, user interaction, or special network access beyond network reachability is required [1].
Impact
Successful exploitation allows the attacker to execute arbitrary operating system commands as root [1]. This gives full control over the device, enabling data exfiltration, malware installation, and further lateral movement within the network. The device becomes fully compromised with no restriction on actions [1].
Mitigation
No official patch is mentioned in the available references [1]. Affected users are advised to replace the device, restrict network access via firewalls, and disable the vulnerable endpoint if possible. As of the publication date, no fix has been released, and the devices may be end-of-life [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Axentra/firmwaredescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.axentra.com/en/mitrex_refsource_MISC
- www.wizcase.com/blog/hack-2018/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.