« Back to list

Asustor

Asustor Data Master: vulnerabilities and CVEs

Asustor Data Master has 45 published vulnerabilities, 19 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.

CVEs45
Last 12 months19
Critical4
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-67248High (8.7)0.49%—Jul 30, 2026
A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-controlled input is not properly validated before being decoded and copied into a fixed-size…
CVE-2026-67247High (7.1)0.45%—Jul 30, 2026
A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled disk serial input is not sufficiently validated before being used to construct the path of an IHM…
CVE-2026-67246Medium (6.9)0.46%—Jul 30, 2026
A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is not sufficiently validated before being used for file access. An…
CVE-2026-67245High (7)0.33%—Jul 30, 2026
A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is not sufficiently validated before being used to construct the upload…
CVE-2026-67244High (8.6)0.50%—Jul 30, 2026
A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-controlled notification configuration input may be processed through an unsafe format string…
CVE-2026-18188High (7.1)0.46%—Jul 30, 2026
A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsync backup configuration or log data may be processed through an unsafe format string operation.…
CVE-2026-18187High (7.1)0.46%—Jul 30, 2026
A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be included in an error response and processed through an unsafe format string…
CVE-2026-18186High (7.1)0.46%—Jul 30, 2026
A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration data may be written into a task log and later processed through an…
CVE-2026-6644Critical (9.4)2.1%—Apr 20, 2026
A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary code on the underlying…
CVE-2026-6643High (8.6)0.76%—Apr 20, 2026
A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing user-controlled data directly to printf(). Due to the lack of PIE and…
CVE-2026-3179Critical (9.2)0.77%—Feb 25, 2026
The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames containing path traversal sequences,…
CVE-2026-3100High (8.3)0.27%—Feb 25, 2026
The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP server using FTPES/FTPS. An improper validated TLS/SSL certificates allows a remote attacker can…
CVE-2026-24936Critical (9.5)0.86%—Feb 3, 2026
When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI program allowing an unauthenticated remote attacker to write arbitrary data…
CVE-2026-24935Medium (6.3)0.16%—Feb 3, 2026
A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While subsequent access to device services requires additional authentication, a Man-in-the-Middle…
CVE-2026-24934Medium (6.3)0.17%—Feb 3, 2026
The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an external server for the device's WAN IP address. An unauthenticated remote attacker can perform a…
CVE-2026-24933High (8.9)0.22%—Feb 3, 2026
The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validation vulnerability allows an unauthenticated remote attacker can…
CVE-2026-24932High (8.9)0.22%—Feb 3, 2026
The DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Although the connection uses HTTPS, an improper validated TLS/SSL certificates allows a remote attacker…
CVE-2025-13053High (7)0.10%—Dec 12, 2025
When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a…
CVE-2025-13052High (7)0.18%—Dec 12, 2025
When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who can intercept network traffic between the SMTP client and server…
CVE-2023-4475Medium (5.5)0.18%—Aug 22, 2023
An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file renaming feature to move files to unintended directories. Affected products and versions include:…
CVE-2023-3699Medium (5.5)0.16%—Aug 22, 2023
An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to modify the storage devices configuration. Affected products and versions include: ADM…
CVE-2023-3698High (8.1)0.64%—Aug 17, 2023
Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.RIS1,…
CVE-2023-3697High (8.8)0.66%—Aug 17, 2023
Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and create files. Affected products and versions include: ADM 4.0.6.RIS1,…
CVE-2023-2910High (8.8)1.6%—Aug 17, 2023
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauthorized users to execute arbitrary…
CVE-2018-12319High (7.5)1.2%—Dec 4, 2018
Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in the title.
CVE-2018-12318High (8.8)1.1%—Dec 4, 2018
Information disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP password in cleartext.
CVE-2018-12317High (8.8)3.4%—Dec 4, 2018
OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" POST parameter.
CVE-2018-12316High (8.8)3.4%—Dec 4, 2018
OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST parameter.
CVE-2018-12315Medium (6.5)0.68%—Dec 4, 2018
Missing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change account passwords without entering the current password.
CVE-2018-12314High (7.5)2.3%—Dec 4, 2018
Directory Traversal in downloadwallpaper.cgi in ASUSTOR ADM version 3.1.1 allows attackers to download arbitrary files by manipulating the "file" and "folder" URL parameters.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services9
  2. T1005 Data from Local System5
  3. T1557 Adversary-in-the-Middle5
  4. T1059 Command and Scripting Interpreter3
  5. T1190 Exploit Public-Facing Application2
  6. T1565.001 Stored Data Manipulation2

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Asustor