Data Master
Asustor · 45 CVEs
A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM
Jul 30, 2026
A path traversal vulnerability was found in the IHM Log handling of ADM
Jul 30, 2026
A path traversal vulnerability was found in the Wallpaper component of ADM
Jul 30, 2026
A path traversal vulnerability was found in the VPN Clients on the ADM
Jul 30, 2026
A format string vulnerability was found in the Notification OAuth settings of ADM
Jul 30, 2026
A format string vulnerability was found in the Rsync Backup on the ADM
Jul 30, 2026
A format string vulnerability was found in the Internal Backup on the ADM
Jul 30, 2026
A stored format string vulnerability was found in the FTP Backup on the ADM
Jul 30, 2026
A command injection vulnerability was found in the PPTP VPN Clients on the ADM
Apr 20, 2026
A stack-based buffer overflow vulnerability in the VPN Clients on the ADM
Apr 20, 2026
A path traversal vulnerability was found in the FTP Backup on the ADM.
Feb 25, 2026
An improper certificate validation vulnerability was found in the FTP Backup on the ADM.
Feb 25, 2026
An improper input validation vulnerability was found in ADM while joining a AD Domain.
Feb 3, 2026
An improper certificate validation vulnerability was found in a third-party NAT traversal module.
Feb 3, 2026
An improper certificate validation vulnerability was found in ADM while querying an external server for the device's WA…
Feb 3, 2026
An improper certificate validation vulnerability was found in ADM while sending HTTPS requests to the server.
Feb 3, 2026
An improper certificate validation vulnerability was found in ADM while updating the DDNS settings.
Feb 3, 2026
A missing encryption of sensitive data vulnerability was found in the UPS settings of ADM
Dec 12, 2025
An improper certificates validation vulnerability was found in the Notification settings of ADM
Dec 12, 2025
An Arbitrary File Movement vulnerability was found on the ADM
Aug 22, 2023
An Improper Privilege Management vulnerability was found on the ADM
Aug 22, 2023
A Command injection vulnerability was found on Printer service of ADM
Aug 17, 2023
A Command injection vulnerability was found on Printer service of ADM
Aug 17, 2023
A Command injection vulnerability was found on Printer service of ADM
Aug 17, 2023
Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing m…
Dec 4, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-67248 | A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM | HIGH | 0.49% | Jul 30, 2026 |
| CVE-2026-67247 | A path traversal vulnerability was found in the IHM Log handling of ADM | HIGH | 0.45% | Jul 30, 2026 |
| CVE-2026-67246 | A path traversal vulnerability was found in the Wallpaper component of ADM | MEDIUM | 0.46% | Jul 30, 2026 |
| CVE-2026-67245 | A path traversal vulnerability was found in the VPN Clients on the ADM | HIGH | 0.33% | Jul 30, 2026 |
| CVE-2026-67244 | A format string vulnerability was found in the Notification OAuth settings of ADM | HIGH | 0.50% | Jul 30, 2026 |
| CVE-2026-18188 | A format string vulnerability was found in the Rsync Backup on the ADM | HIGH | 0.46% | Jul 30, 2026 |
| CVE-2026-18187 | A format string vulnerability was found in the Internal Backup on the ADM | HIGH | 0.46% | Jul 30, 2026 |
| CVE-2026-18186 | A stored format string vulnerability was found in the FTP Backup on the ADM | HIGH | 0.46% | Jul 30, 2026 |
| CVE-2026-6644 | A command injection vulnerability was found in the PPTP VPN Clients on the ADM | CRITICAL | 2.08% | Apr 20, 2026 |
| CVE-2026-6643 | A stack-based buffer overflow vulnerability in the VPN Clients on the ADM | HIGH | 0.76% | Apr 20, 2026 |
| CVE-2026-3179 | A path traversal vulnerability was found in the FTP Backup on the ADM. | CRITICAL | 0.77% | Feb 25, 2026 |
| CVE-2026-3100 | An improper certificate validation vulnerability was found in the FTP Backup on the ADM. | HIGH | 0.27% | Feb 25, 2026 |
| CVE-2026-24936 | An improper input validation vulnerability was found in ADM while joining a AD Domain. | CRITICAL | 0.86% | Feb 3, 2026 |
| CVE-2026-24935 | An improper certificate validation vulnerability was found in a third-party NAT traversal module. | MEDIUM | 0.16% | Feb 3, 2026 |
| CVE-2026-24934 | An improper certificate validation vulnerability was found in ADM while querying an external server for the device's WAN IP address. | MEDIUM | 0.17% | Feb 3, 2026 |
| CVE-2026-24933 | An improper certificate validation vulnerability was found in ADM while sending HTTPS requests to the server. | HIGH | 0.22% | Feb 3, 2026 |
| CVE-2026-24932 | An improper certificate validation vulnerability was found in ADM while updating the DDNS settings. | HIGH | 0.22% | Feb 3, 2026 |
| CVE-2025-13053 | A missing encryption of sensitive data vulnerability was found in the UPS settings of ADM | HIGH | 0.10% | Dec 12, 2025 |
| CVE-2025-13052 | An improper certificates validation vulnerability was found in the Notification settings of ADM | HIGH | 0.18% | Dec 12, 2025 |
| CVE-2023-4475 | An Arbitrary File Movement vulnerability was found on the ADM | HIGH | 0.18% | Aug 22, 2023 |
| CVE-2023-3699 | An Improper Privilege Management vulnerability was found on the ADM | HIGH | 0.16% | Aug 22, 2023 |
| CVE-2023-3698 | A Command injection vulnerability was found on Printer service of ADM | HIGH | 0.64% | Aug 17, 2023 |
| CVE-2023-3697 | A Command injection vulnerability was found on Printer service of ADM | HIGH | 0.66% | Aug 17, 2023 |
| CVE-2023-2910 | A Command injection vulnerability was found on Printer service of ADM | HIGH | 1.58% | Aug 17, 2023 |
| CVE-2018-12319 | Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in the title. | HIGH | 1.18% | Dec 4, 2018 |
Showing 1 to 25 of 45 CVEs