Skip to main content

Vendor/product archive

asustor / adm CVEs

Beta · best-effort

6 CVEs tagged to asustor / adm1 Critical, 5 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2023-2909

Published May 31, 2023

EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions in…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30770

Published Apr 17, 2023

A stack-based buffer overflow vulnerability was found in the ASUSTOR Data Master (ADM) due to the lack of data size validation. An attacker can exploit this vulnerability to execu…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-37398

Published Aug 5, 2022

A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit this vulnerability to run arbit…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11510

Published Jun 28, 2018

The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by embedding OS commands in the…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1