ADM
Asustor · 33 CVEs
A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM
Jul 30, 2026
A path traversal vulnerability was found in the IHM Log handling of ADM
Jul 30, 2026
A path traversal vulnerability was found in the Wallpaper component of ADM
Jul 30, 2026
A path traversal vulnerability was found in the VPN Clients on the ADM
Jul 30, 2026
A format string vulnerability was found in the Notification OAuth settings of ADM
Jul 30, 2026
A format string vulnerability was found in the Rsync Backup on the ADM
Jul 30, 2026
A format string vulnerability was found in the Internal Backup on the ADM
Jul 30, 2026
A stored format string vulnerability was found in the FTP Backup on the ADM
Jul 30, 2026
A command injection vulnerability was found in the PPTP VPN Clients on the ADM
Apr 20, 2026
A stack-based buffer overflow vulnerability in the VPN Clients on the ADM
Apr 20, 2026
A path traversal vulnerability was found in the FTP Backup on the ADM.
Feb 25, 2026
An improper certificate validation vulnerability was found in the FTP Backup on the ADM.
Feb 25, 2026
An improper input validation vulnerability was found in ADM while joining a AD Domain.
Feb 3, 2026
An improper certificate validation vulnerability was found in a third-party NAT traversal module.
Feb 3, 2026
An improper certificate validation vulnerability was found in ADM while querying an external server for the device's WA…
Feb 3, 2026
An improper certificate validation vulnerability was found in ADM while sending HTTPS requests to the server.
Feb 3, 2026
An improper certificate validation vulnerability was found in ADM while updating the DDNS settings.
Feb 3, 2026
A missing encryption of sensitive data vulnerability was found in the UPS settings of ADM
Dec 12, 2025
An improper certificates validation vulnerability was found in the Notification settings of ADM
Dec 12, 2025
An improper access control vulnerability was found in the EZ Sync Manager of ADM
Jul 16, 2025
A stored Cross-Site Scripting (XSS) vulnerability exists in the File Explorer and Text Editor of ADM
Jul 14, 2025
A stored Cross-Site Scripting (XSS) vulnerability exists in the Access Control of ADM
Jul 14, 2025
A security bypass vulnerability was found in DataSync Center installed on ADM
Jul 9, 2025
An improper input validation vulnerability was found on manipulating configuration of ADM
Jul 9, 2025
An Arbitrary File Movement vulnerability was found on the ADM
Aug 22, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-67248 | A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM | HIGH | 0.49% | Jul 30, 2026 |
| CVE-2026-67247 | A path traversal vulnerability was found in the IHM Log handling of ADM | HIGH | 0.45% | Jul 30, 2026 |
| CVE-2026-67246 | A path traversal vulnerability was found in the Wallpaper component of ADM | MEDIUM | 0.46% | Jul 30, 2026 |
| CVE-2026-67245 | A path traversal vulnerability was found in the VPN Clients on the ADM | HIGH | 0.33% | Jul 30, 2026 |
| CVE-2026-67244 | A format string vulnerability was found in the Notification OAuth settings of ADM | HIGH | 0.50% | Jul 30, 2026 |
| CVE-2026-18188 | A format string vulnerability was found in the Rsync Backup on the ADM | HIGH | 0.46% | Jul 30, 2026 |
| CVE-2026-18187 | A format string vulnerability was found in the Internal Backup on the ADM | HIGH | 0.46% | Jul 30, 2026 |
| CVE-2026-18186 | A stored format string vulnerability was found in the FTP Backup on the ADM | HIGH | 0.46% | Jul 30, 2026 |
| CVE-2026-6644 | A command injection vulnerability was found in the PPTP VPN Clients on the ADM | CRITICAL | 2.08% | Apr 20, 2026 |
| CVE-2026-6643 | A stack-based buffer overflow vulnerability in the VPN Clients on the ADM | HIGH | 0.76% | Apr 20, 2026 |
| CVE-2026-3179 | A path traversal vulnerability was found in the FTP Backup on the ADM. | CRITICAL | 0.77% | Feb 25, 2026 |
| CVE-2026-3100 | An improper certificate validation vulnerability was found in the FTP Backup on the ADM. | HIGH | 0.27% | Feb 25, 2026 |
| CVE-2026-24936 | An improper input validation vulnerability was found in ADM while joining a AD Domain. | CRITICAL | 0.86% | Feb 3, 2026 |
| CVE-2026-24935 | An improper certificate validation vulnerability was found in a third-party NAT traversal module. | MEDIUM | 0.16% | Feb 3, 2026 |
| CVE-2026-24934 | An improper certificate validation vulnerability was found in ADM while querying an external server for the device's WAN IP address. | MEDIUM | 0.17% | Feb 3, 2026 |
| CVE-2026-24933 | An improper certificate validation vulnerability was found in ADM while sending HTTPS requests to the server. | HIGH | 0.22% | Feb 3, 2026 |
| CVE-2026-24932 | An improper certificate validation vulnerability was found in ADM while updating the DDNS settings. | HIGH | 0.22% | Feb 3, 2026 |
| CVE-2025-13053 | A missing encryption of sensitive data vulnerability was found in the UPS settings of ADM | HIGH | 0.10% | Dec 12, 2025 |
| CVE-2025-13052 | An improper certificates validation vulnerability was found in the Notification settings of ADM | HIGH | 0.18% | Dec 12, 2025 |
| CVE-2025-7699 | An improper access control vulnerability was found in the EZ Sync Manager of ADM | HIGH | 0.34% | Jul 16, 2025 |
| CVE-2025-7618 | A stored Cross-Site Scripting (XSS) vulnerability exists in the File Explorer and Text Editor of ADM | MEDIUM | 0.31% | Jul 14, 2025 |
| CVE-2025-7380 | A stored Cross-Site Scripting (XSS) vulnerability exists in the Access Control of ADM | MEDIUM | 0.31% | Jul 14, 2025 |
| CVE-2025-7379 | A security bypass vulnerability was found in DataSync Center installed on ADM | MEDIUM | 0.18% | Jul 9, 2025 |
| CVE-2025-7378 | An improper input validation vulnerability was found on manipulating configuration of ADM | MEDIUM | 0.14% | Jul 9, 2025 |
| CVE-2023-4475 | An Arbitrary File Movement vulnerability was found on the ADM | HIGH | 0.18% | Aug 22, 2023 |
Showing 1 to 25 of 33 CVEs