Known Vulnerabilities for products from Asustor
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Asustor".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Additional devices specifications by Asustor can be found at device.report : Asustor
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-6644 json | A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative us... | Not Provided | 2026-04-20 | 2026-04-30 |
| CVE-2026-6643 json | A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounde... | Not Provided | 2026-04-20 | 2026-04-22 |
| CVE-2023-30770 json | A stack-based buffer overflow vulnerability was found in the ASUSTOR Data Master (ADM) due to the lack of data size validatio... | 9.8 - CRITICAL | 2023-04-17 | 2023-05-04 |
| CVE-2023-4475 json | An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file renami... | 5.5 - MEDIUM | 2023-08-22 | 2023-08-28 |
| CVE-2023-3699 json | An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to m... | 5.5 - MEDIUM | 2023-08-22 | 2023-08-28 |
| CVE-2023-3698 json | Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended ... | 8.1 - HIGH | 2023-08-17 | 2023-08-23 |
| CVE-2023-3697 json | Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended ... | 8.8 - HIGH | 2023-08-17 | 2023-08-23 |
| CVE-2023-2910 json | Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service function... | 8.8 - HIGH | 2023-08-17 | 2023-08-23 |
| CVE-2023-2909 json | EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structu... | 10 - CRITICAL | 2023-05-31 | 2023-06-07 |
| CVE-2023-2749 json | Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability to g... | 7.5 - HIGH | 2023-05-31 | 2023-06-07 |
| CVE-2023-2509 json | A Cross-Site Scripting(XSS) vulnerability was found on ADM, LooksGood and SoundsGood Apps. An attacker can exploit this vulne... | 6.1 - MEDIUM | 2023-05-17 | 2023-05-26 |
| CVE-2022-37398 json | A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. A... | 8.8 - HIGH | 2022-08-05 | 2022-08-11 |
| CVE-2019-11689 json | An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl... | 8.1 - HIGH | 2020-03-18 | 2020-08-24 |
| CVE-2019-11688 json | An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl... | 7.4 - HIGH | 2020-03-18 | 2020-03-24 |
| CVE-2018-15699 json | ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in the mi... | 6.1 - MEDIUM | 2018-08-27 | 2018-10-30 |
| CVE-2018-15698 json | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system ... | 6.5 - MEDIUM | 2018-08-27 | 2018-10-30 |
| CVE-2018-15697 json | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by provi... | 6.5 - MEDIUM | 2018-08-27 | 2018-10-30 |
| CVE-2018-15696 json | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via u... | 4.3 - MEDIUM | 2018-08-27 | 2018-10-30 |
| CVE-2018-15695 json | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file syste... | 6.5 - MEDIUM | 2018-08-27 | 2018-10-30 |
| CVE-2018-15694 json | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locatio... | 7.5 - HIGH | 2018-08-27 | 2018-10-30 |
Known software with vulnerabilities from Asustor
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Asustor | Adm | 2.5.4.rf42 |
| Hardware | Asustor | As-602t | - |
| Application | Asustor | Asustor Data Master | 3.1.0 |
| Operating System | Asustor | Data Master | 2.1 |
| Application | Asustor | Exfat Driver | 1.0.0 |
| Application | Asustor | Soundsgood | - |