Known Vulnerabilities for products from Asustor
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Asustor".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Additional devices specifications by Asustor can be found at device.report : Asustor
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-67248 json | A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-... | Not Provided | 2026-07-30 | 2026-08-04 |
| CVE-2026-67247 json | A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled dis... | Not Provided | 2026-07-30 | 2026-08-04 |
| CVE-2026-67246 json | A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled ... | Not Provided | 2026-07-30 | 2026-08-04 |
| CVE-2026-67245 json | A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled cert... | Not Provided | 2026-07-30 | 2026-08-04 |
| CVE-2026-67244 json | A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-cont... | Not Provided | 2026-07-30 | 2026-08-04 |
| CVE-2026-18759 json | Not Provided | 2026-08-04 | 2026-08-04 | |
| CVE-2026-18188 json | A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsyn... | Not Provided | 2026-07-30 | 2026-08-04 |
| CVE-2026-18187 json | A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled t... | Not Provided | 2026-07-30 | 2026-08-04 |
| CVE-2026-18186 json | A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled... | Not Provided | 2026-07-30 | 2026-08-04 |
| CVE-2026-6644 json | A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative us... | Not Provided | 2026-04-20 | 2026-04-30 |
| CVE-2026-6643 json | A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounde... | Not Provided | 2026-04-20 | 2026-04-22 |
| CVE-2023-30770 json | A stack-based buffer overflow vulnerability was found in the ASUSTOR Data Master (ADM) due to the lack of data size validatio... | 9.8 - CRITICAL | 2023-04-17 | 2023-05-04 |
| CVE-2023-4475 json | An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file renami... | 5.5 - MEDIUM | 2023-08-22 | 2023-08-28 |
| CVE-2023-3699 json | An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to m... | 5.5 - MEDIUM | 2023-08-22 | 2023-08-28 |
| CVE-2023-3698 json | Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended ... | 8.1 - HIGH | 2023-08-17 | 2023-08-23 |
| CVE-2023-3697 json | Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended ... | 8.8 - HIGH | 2023-08-17 | 2023-08-23 |
| CVE-2023-2910 json | Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service function... | 8.8 - HIGH | 2023-08-17 | 2023-08-23 |
| CVE-2023-2909 json | EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structu... | 10 - CRITICAL | 2023-05-31 | 2023-06-07 |
| CVE-2023-2749 json | Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability to g... | 7.5 - HIGH | 2023-05-31 | 2023-06-07 |
| CVE-2023-2509 json | A Cross-Site Scripting(XSS) vulnerability was found on ADM, LooksGood and SoundsGood Apps. An attacker can exploit this vulne... | 6.1 - MEDIUM | 2023-05-17 | 2023-05-26 |
Known software with vulnerabilities from Asustor
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Asustor | Adm | 2.5.4.rf42 |
| Hardware | Asustor | As-602t | - |
| Application | Asustor | Asustor Data Master | 3.1.0 |
| Operating System | Asustor | Data Master | 2.1 |
| Application | Asustor | Exfat Driver | 1.0.0 |
| Application | Asustor | Soundsgood | - |