ADM

Asustor · 33 CVEs

CVE-2026-67248
HIGH

A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM

Jul 30, 2026

CVE-2026-67247
HIGH

A path traversal vulnerability was found in the IHM Log handling of ADM

Jul 30, 2026

CVE-2026-67246
MEDIUM

A path traversal vulnerability was found in the Wallpaper component of ADM

Jul 30, 2026

CVE-2026-67245
HIGH

A path traversal vulnerability was found in the VPN Clients on the ADM

Jul 30, 2026

CVE-2026-67244
HIGH

A format string vulnerability was found in the Notification OAuth settings of ADM

Jul 30, 2026

CVE-2026-18188
HIGH

A format string vulnerability was found in the Rsync Backup on the ADM

Jul 30, 2026

CVE-2026-18187
HIGH

A format string vulnerability was found in the Internal Backup on the ADM

Jul 30, 2026

CVE-2026-18186
HIGH

A stored format string vulnerability was found in the FTP Backup on the ADM

Jul 30, 2026

CVE-2026-6644
CRITICAL

A command injection vulnerability was found in the PPTP VPN Clients on the ADM

Apr 20, 2026

CVE-2026-6643
HIGH

A stack-based buffer overflow vulnerability in the VPN Clients on the ADM

Apr 20, 2026

CVE-2026-3179
CRITICAL

A path traversal vulnerability was found in the FTP Backup on the ADM.

Feb 25, 2026

CVE-2026-3100
HIGH

An improper certificate validation vulnerability was found in the FTP Backup on the ADM.

Feb 25, 2026

CVE-2026-24936
CRITICAL

An improper input validation vulnerability was found in ADM while joining a AD Domain.

Feb 3, 2026

CVE-2026-24935
MEDIUM

An improper certificate validation vulnerability was found in a third-party NAT traversal module.

Feb 3, 2026

CVE-2026-24934
MEDIUM

An improper certificate validation vulnerability was found in ADM while querying an external server for the device's WA…

Feb 3, 2026

CVE-2026-24933
HIGH

An improper certificate validation vulnerability was found in ADM while sending HTTPS requests to the server.

Feb 3, 2026

CVE-2026-24932
HIGH

An improper certificate validation vulnerability was found in ADM while updating the DDNS settings.

Feb 3, 2026

CVE-2025-13053
HIGH

A missing encryption of sensitive data vulnerability was found in the UPS settings of ADM

Dec 12, 2025

CVE-2025-13052
HIGH

An improper certificates validation vulnerability was found in the Notification settings of ADM

Dec 12, 2025

CVE-2025-7699
HIGH

An improper access control vulnerability was found in the EZ Sync Manager of ADM

Jul 16, 2025

CVE-2025-7618
MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability exists in the File Explorer and Text Editor of ADM

Jul 14, 2025

CVE-2025-7380
MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability exists in the Access Control of ADM

Jul 14, 2025

CVE-2025-7379
MEDIUM

A security bypass vulnerability was found in DataSync Center installed on ADM

Jul 9, 2025

CVE-2025-7378
MEDIUM

An improper input validation vulnerability was found on manipulating configuration of ADM

Jul 9, 2025

CVE-2023-4475
HIGH

An Arbitrary File Movement vulnerability was found on the ADM

Aug 22, 2023

Showing 1 to 25 of 33 CVEs