Asustor
Asustor Data Master: vulnerabilidades y CVE
Asustor Data Master tiene 45 vulnerabilidades publicadas, 19 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE45
Últimos 12 meses19
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-67248 | Alta (8.7) | 0.49% | — | 30 jul 2026 | A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-controlled input is not properly validated before being decoded and copied into a fixed-size… |
| CVE-2026-67247 | Alta (7.1) | 0.45% | — | 30 jul 2026 | A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled disk serial input is not sufficiently validated before being used to construct the path of an IHM… |
| CVE-2026-67246 | Media (6.9) | 0.46% | — | 30 jul 2026 | A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is not sufficiently validated before being used for file access. An… |
| CVE-2026-67245 | Alta (7) | 0.33% | — | 30 jul 2026 | A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is not sufficiently validated before being used to construct the upload… |
| CVE-2026-67244 | Alta (8.6) | 0.50% | — | 30 jul 2026 | A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-controlled notification configuration input may be processed through an unsafe format string… |
| CVE-2026-18188 | Alta (7.1) | 0.46% | — | 30 jul 2026 | A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsync backup configuration or log data may be processed through an unsafe format string operation.… |
| CVE-2026-18187 | Alta (7.1) | 0.46% | — | 30 jul 2026 | A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be included in an error response and processed through an unsafe format string… |
| CVE-2026-18186 | Alta (7.1) | 0.46% | — | 30 jul 2026 | A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration data may be written into a task log and later processed through an… |
| CVE-2026-6644 | Crítica (9.4) | 2.1% | — | 20 abr 2026 | A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary code on the underlying… |
| CVE-2026-6643 | Alta (8.6) | 0.76% | — | 20 abr 2026 | A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing user-controlled data directly to printf(). Due to the lack of PIE and… |
| CVE-2026-3179 | Crítica (9.2) | 0.77% | — | 25 feb 2026 | The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames containing path traversal sequences,… |
| CVE-2026-3100 | Alta (8.3) | 0.27% | — | 25 feb 2026 | The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP server using FTPES/FTPS. An improper validated TLS/SSL certificates allows a remote attacker can… |
| CVE-2026-24936 | Crítica (9.5) | 0.86% | — | 3 feb 2026 | When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI program allowing an unauthenticated remote attacker to write arbitrary data… |
| CVE-2026-24935 | Media (6.3) | 0.16% | — | 3 feb 2026 | A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While subsequent access to device services requires additional authentication, a Man-in-the-Middle… |
| CVE-2026-24934 | Media (6.3) | 0.17% | — | 3 feb 2026 | The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an external server for the device's WAN IP address. An unauthenticated remote attacker can perform a… |
| CVE-2026-24933 | Alta (8.9) | 0.22% | — | 3 feb 2026 | The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validation vulnerability allows an unauthenticated remote attacker can… |
| CVE-2026-24932 | Alta (8.9) | 0.22% | — | 3 feb 2026 | The DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Although the connection uses HTTPS, an improper validated TLS/SSL certificates allows a remote attacker… |
| CVE-2025-13053 | Alta (7) | 0.10% | — | 12 dic 2025 | When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a… |
| CVE-2025-13052 | Alta (7) | 0.18% | — | 12 dic 2025 | When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who can intercept network traffic between the SMTP client and server… |
| CVE-2023-4475 | Media (5.5) | 0.18% | — | 22 ago 2023 | An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file renaming feature to move files to unintended directories. Affected products and versions include:… |
| CVE-2023-3699 | Media (5.5) | 0.16% | — | 22 ago 2023 | An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to modify the storage devices configuration. Affected products and versions include: ADM… |
| CVE-2023-3698 | Alta (8.1) | 0.64% | — | 17 ago 2023 | Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.RIS1,… |
| CVE-2023-3697 | Alta (8.8) | 0.66% | — | 17 ago 2023 | Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and create files. Affected products and versions include: ADM 4.0.6.RIS1,… |
| CVE-2023-2910 | Alta (8.8) | 1.6% | — | 17 ago 2023 | Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauthorized users to execute arbitrary… |
| CVE-2018-12319 | Alta (7.5) | 1.2% | — | 4 dic 2018 | Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in the title. |
| CVE-2018-12318 | Alta (8.8) | 1.1% | — | 4 dic 2018 | Information disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP password in cleartext. |
| CVE-2018-12317 | Alta (8.8) | 3.4% | — | 4 dic 2018 | OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" POST parameter. |
| CVE-2018-12316 | Alta (8.8) | 3.4% | — | 4 dic 2018 | OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST parameter. |
| CVE-2018-12315 | Media (6.5) | 0.68% | — | 4 dic 2018 | Missing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change account passwords without entering the current password. |
| CVE-2018-12314 | Alta (7.5) | 2.3% | — | 4 dic 2018 | Directory Traversal in downloadwallpaper.cgi in ASUSTOR ADM version 3.1.1 allows attackers to download arbitrary files by manipulating the "file" and "folder" URL parameters. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.