VendorsAsustordata_masterall versions
Vulnerabilities

Asustor Data Master

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

45CVEs
CVE-2018-12313
OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity" URL parameter.
Published 2018-12-04 · Modified
10.0EPSS 0.044
CVE-2026-6643
A stack-based buffer overflow vulnerability in the VPN Clients on the ADM
Published 2026-04-20 · Analyzed
9.9EPSS 0.005
CVE-2026-24936
An improper input validation vulnerability was found in ADM while joining a AD Domain.
Published 2026-02-03 · Analyzed
9.8EPSS 0.008
CVE-2026-6644
A command injection vulnerability was found in the PPTP VPN Clients on the ADM
Published 2026-04-20 · Modified
9.4EPSS 0.015
CVE-2026-3179
A path traversal vulnerability was found in the FTP Backup on the ADM.
Published 2026-02-25 · Analyzed
9.2EPSS 0.005
CVE-2018-12317
OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" POST parameter.
Published 2018-12-04 · Modified
9.0EPSS 0.034
CVE-2018-12307
OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "name" POST parameter.
Published 2018-12-04 · Modified
9.0EPSS 0.034
CVE-2018-12316
OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST parameter.
Published 2018-12-04 · Modified
9.0EPSS 0.034
CVE-2018-12312
OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "secret_key" URL parameter.
Published 2018-12-04 · Modified
9.0EPSS 0.034
CVE-2026-24932
An improper certificate validation vulnerability was found in ADM while updating the DDNS settings.
Published 2026-02-03 · Analyzed
8.9EPSS 0.002
CVE-2026-24933
An improper certificate validation vulnerability was found in ADM while sending HTTPS requests to the server.
Published 2026-02-03 · Analyzed
8.9EPSS 0.002
CVE-2023-2910
A Command injection vulnerability was found on Printer service of ADM
Published 2023-08-17 · Modified
8.8EPSS 0.016
CVE-2018-12318
Information disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP password in cleartext.
Published 2018-12-04 · Modified
8.8EPSS 0.011
CVE-2023-3697
A Command injection vulnerability was found on Printer service of ADM
Published 2023-08-17 · Modified
8.8EPSS 0.007
CVE-2026-67248
A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM
Published 2026-07-30 · Analyzed
8.8EPSS 0.003
CVE-2023-3699
An Improper Privilege Management vulnerability was found on the ADM
Published 2023-08-22 · Modified
8.7EPSS 0.002
CVE-2026-67244
A format string vulnerability was found in the Notification OAuth settings of ADM
Published 2026-07-30 · Analyzed
8.6EPSS 0.003
CVE-2018-15695
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a path traversal vulnerability in wallpaper.cgi.
Published 2018-08-27 · Modified
8.5EPSS 0.010
CVE-2023-3698
A Command injection vulnerability was found on Printer service of ADM
Published 2023-08-17 · Modified
8.5EPSS 0.006
CVE-2026-3100
An improper certificate validation vulnerability was found in the FTP Backup on the ADM.
Published 2026-02-25 · Analyzed
8.3EPSS 0.002
CVE-2026-18188
A format string vulnerability was found in the Rsync Backup on the ADM
Published 2026-07-30 · Analyzed
8.1EPSS 0.003
CVE-2026-18186
A stored format string vulnerability was found in the FTP Backup on the ADM
Published 2026-07-30 · Analyzed
8.1EPSS 0.003
CVE-2026-18187
A format string vulnerability was found in the Internal Backup on the ADM
Published 2026-07-30 · Analyzed
8.1EPSS 0.003
CVE-2026-67245
A path traversal vulnerability was found in the VPN Clients on the ADM
Published 2026-07-30 · Analyzed
8.1EPSS 0.002
CVE-2018-12314
Directory Traversal in downloadwallpaper.cgi in ASUSTOR ADM version 3.1.1 allows attackers to download arbitrary files by manipulating the "file" and "folder" URL parameters.
Published 2018-12-04 · Modified
7.8EPSS 0.023
CVE-2018-12306
Directory Traversal in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to view arbitrary files by modifying the "file1" URL parameter, a similar issue to CVE-2018-11344.
Published 2018-12-04 · Modified
7.5EPSS 0.017
CVE-2018-15694
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path traversal vulnerability. This could lead to code execution if the "Web Server" feature is enabled.
Published 2018-08-27 · Modified
7.5EPSS 0.015
CVE-2018-12309
Directory Traversal in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to upload files to arbitrary locations by modifying the "path" URL parameter. NOTE: the "filename" POST parameter is covered by CVE-2018-11345.
Published 2018-12-04 · Modified
7.5EPSS 0.015
CVE-2018-12319
Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in the title.
Published 2018-12-04 · Modified
7.5EPSS 0.012
CVE-2023-4475
An Arbitrary File Movement vulnerability was found on the ADM
Published 2023-08-22 · Modified
7.5EPSS 0.002
CVE-2026-67247
A path traversal vulnerability was found in the IHM Log handling of ADM
Published 2026-07-30 · Analyzed
7.1EPSS 0.003
CVE-2025-13052
An improper certificates validation vulnerability was found in the Notification settings of ADM
Published 2025-12-12 · Analyzed
7.0EPSS 0.002
CVE-2025-13053
A missing encryption of sensitive data vulnerability was found in the UPS settings of ADM
Published 2025-12-12 · Analyzed
7.0EPSS 0.001
CVE-2026-67246
A path traversal vulnerability was found in the Wallpaper component of ADM
Published 2026-07-30 · Analyzed
6.9EPSS 0.003
CVE-2018-15698
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system when providing the full path to loginimage.cgi.
Published 2018-08-27 · Modified
6.8EPSS 0.011
CVE-2018-15697
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full path. For example, /home/admin/.ash_history.
Published 2018-08-27 · Modified
6.5EPSS 0.009
CVE-2018-12315
Missing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change account passwords without entering the current password.
Published 2018-12-04 · Modified
6.5EPSS 0.007
CVE-2018-12308
Encryption key disclosure in share.cgi in ASUSTOR ADM version 3.1.1 allows attackers to obtain the encryption key via the "encrypt_key" URL parameter.
Published 2018-12-04 · Modified
6.5EPSS 0.006
CVE-2026-24934
An improper certificate validation vulnerability was found in ADM while querying an external server for the device's WAN IP address.
Published 2026-02-03 · Analyzed
6.3EPSS 0.002
CVE-2026-24935
An improper certificate validation vulnerability was found in a third-party NAT traversal module.
Published 2026-02-03 · Analyzed
6.3EPSS 0.002
1 / 2Next →