Skip to main content

Vendor archive

asustor CVEs

Beta · best-effort

54 CVEs tagged to vendor asustor7 Critical, 31 High, 16 Medium, 0 Low, 0 Unrated.

CVE-2026-6644

Published Apr 20, 2026

A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-6643

Published Apr 20, 2026

A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing user-controlled data directly t…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-3179

Published Feb 25, 2026

The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filename…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-3100

Published Feb 25, 2026

The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP server using FTPES/FTPS. An improper validated TLS/SSL certifi…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24936

Published Feb 3, 2026

When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI program allowing an unauthenticated…

CVSS 9.5 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24935

Published Feb 3, 2026

A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While subsequent access to device services requires additional a…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24934

Published Feb 3, 2026

The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an external server for the device's WAN IP address. An unauthenticate…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24933

Published Feb 3, 2026

The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validation vulnerability allows an un…

CVSS 8.9 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24932

Published Feb 3, 2026

The DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Although the connection uses HTTPS, an improper validated TLS/SSL…

CVSS 8.9 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-13053

Published Dec 12, 2025

When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic betwe…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-13052

Published Dec 12, 2025

When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who can intercept network tr…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-4475

Published Aug 22, 2023

An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file renaming feature to move files to unintended directories. Af…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3699

Published Aug 22, 2023

An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to modify the storage devices configuration. Affected prod…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3698

Published Aug 17, 2023

Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and delete files. Affected product…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3697

Published Aug 17, 2023

Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and create files. Affected product…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2910

Published Aug 17, 2023

Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unaut…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2909

Published May 31, 2023

EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions in…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30770

Published Apr 17, 2023

A stack-based buffer overflow vulnerability was found in the ASUSTOR Data Master (ADM) due to the lack of data size validation. An attacker can exploit this vulnerability to execu…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-37398

Published Aug 5, 2022

A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit this vulnerability to run arbit…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11689

Published Mar 18, 2020

An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl fail to properly validate server responses and pass u…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11688

Published Mar 18, 2020

An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl accept any certificate for asustornasapi.asustor.com.…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 54 CVEsPage 1 of 3