Vulnerability index

Browse CVEs

57 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Data Master HIGH 8.8
CVE-2026-67248

A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-controlled input is not …

Fix: 5.1.4.rjv2+
Fix from $1,950 2026-07-30
Data Master MEDIUM 6.5
CVE-2026-67247

A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled disk serial input is not su…

Fix: 5.1.4.rjv2+
Fix from $1,600 2026-07-30
Data Master HIGH 8.1
CVE-2026-67245

A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is no…

Fix: 5.1.4.rjv2+
Fix from $1,950 2026-07-30
Data Master MEDIUM 6.5
CVE-2026-67246

A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is …

Fix: 5.1.4.rjv2+
Fix from $1,600 2026-07-30
Data Master HIGH 7.2
CVE-2026-67244

A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-controlled notification conf…

Fix: 5.1.4.rjv2+
Fix from $1,950 2026-07-30
Data Master HIGH 8.1
CVE-2026-18186

A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration da…

Fix: 5.1.4.rjv2+
Fix from $1,950 2026-07-30
Data Master HIGH 8.1
CVE-2026-18187

A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be include…

Fix: 5.1.4.rjv2+
Fix from $1,950 2026-07-30
Data Master HIGH 8.1
CVE-2026-18188

A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsync backup configuration o…

Fix: 5.1.4.rjv2+
Fix from $1,950 2026-07-30
Data Master CRITICAL 9.9
CVE-2026-6643

A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing u…

Fix: 4.3.3.RR42 / 5.1.2.reo1+
Fix from $2,300 2026-04-20
Data Master CRITICAL 9.1
CVE-2026-6644

A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the r…

Fix: 4.3.3.RR42 / 5.1.2.reo1+
Fix from $2,300 2026-04-20
Data Master HIGH 8.1
CVE-2026-3179

The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MI…

Fix: 5.1.2.reo1+
Fix from $1,950 2026-02-25
Data Master MEDIUM 6.5
CVE-2026-3100

The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP server using FTPES/FTPS. An impr…

Fix: 5.1.2.reo1+
Fix from $1,600 2026-02-25
Data Master CRITICAL 9.8
CVE-2026-24936

When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI progr…

Fix: 5.1.2.re51+
Fix from $2,300 2026-02-03
Data Master MEDIUM 5.9
CVE-2026-24932

The DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Although the connection uses HTTPS,…

Fix: 5.1.2.re51+
Fix from $1,600 2026-02-03
Data Master MEDIUM 5.9
CVE-2026-24933

The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validat…

Fix: 5.1.2.re51+
Fix from $1,600 2026-02-03
Data Master MEDIUM 5.6
CVE-2026-24935

A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While subsequent access to device …

Fix: 5.1.2.re51+
Fix from $1,600 2026-02-03
Data Master MEDIUM 5.9
CVE-2025-13052

When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacke…

Fix: 4.3.3.ROF1 / 5.1.1.RCI1+
Fix from $1,600 2025-12-12
Data Master MEDIUM 5.5
CVE-2023-4475

An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file renaming feature to move files…

Fix: 4.2.2.ri61+
Fix from $1,600 2023-08-22
Data Master MEDIUM 5.5
CVE-2023-3699

An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to modify the storage device…

Fix: 4.2.3.rk91+
Fix from $1,600 2023-08-22
Data Master HIGH 8.8
CVE-2023-2910

Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Ma…

Fix: 4.2.3.rk91+
Fix from $1,950 2023-08-17
Data Master HIGH 8.8
CVE-2023-3697

Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and …

Fix: 4.2.3.rk91+
Fix from $1,950 2023-08-17
Data Master HIGH 8.1
CVE-2023-3698

Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and …

Fix: 4.2.3.rk91+
Fix from $1,950 2023-08-17
Adm CRITICAL 10.0
CVE-2023-2909

EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Aff…

Fix: after 4.2.1.rge2
Fix from $2,300 2023-05-31
Download Center HIGH 7.5
CVE-2023-2749

Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability to gain unauthorized access …

Fix: 1.1.5.r1298+
Fix from $1,950 2023-05-31
Adm MEDIUM 6.1
CVE-2023-2509

A Cross-Site Scripting(XSS) vulnerability was found on ADM, LooksGood and SoundsGood Apps. An attacker can exploit this vulnerability to inject malic…

Mitigation only
Fix from $1,600 2023-05-17
Adm CRITICAL 9.8
CVE-2023-30770

A stack-based buffer overflow vulnerability was found in the ASUSTOR Data Master (ADM) due to the lack of data size validation. An attacker can explo…

Fix: 4.2.1.rge2+
Fix from $2,300 2023-04-17
Adm HIGH 8.8
CVE-2022-37398

A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit t…

Fix: after 4.1.0.rjd1
Fix from $1,950 2022-08-05
Exfat Driver HIGH 8.1
CVE-2019-11689

An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl fail to properly valida…

No fix yet
Fix from $1,950 2020-03-18
Exfat Driver HIGH 7.4
CVE-2019-11688

An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl accept any certificate …

No fix yet
Fix from $1,950 2020-03-18
Data Master CRITICAL 9.8
CVE-2018-12313

OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity…

No fix yet
Fix from $2,300 2018-12-04