Asustor

Adm

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 12.12.2025 02:46:08
  • Zuletzt bearbeitet 12.12.2025 15:17:31

When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack,...

  • EPSS 0.02%
  • Veröffentlicht 12.12.2025 02:30:35
  • Zuletzt bearbeitet 12.12.2025 15:17:31

When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who can intercept network traffic between the SMTP client and server to execute a man-in-the-middle...

  • EPSS 0.04%
  • Veröffentlicht 16.07.2025 09:41:12
  • Zuletzt bearbeitet 16.07.2025 14:58:59

An improper access control vulnerability was found in the EZ Sync Manager of ADM, which allows authenticated users to copy arbitrary files from the server file system into their own EZSync folder. The vulnerability is due to a lack of authorization ...

  • EPSS 0.05%
  • Veröffentlicht 14.07.2025 10:15:10
  • Zuletzt bearbeitet 15.07.2025 13:14:24

A stored Cross-Site Scripting (XSS) vulnerability vulnerability was found in the File Explorer and Text Editor of ADM. An attacker could exploit this vulnerability to inject malicious scripts into the applications, which may then access cookies or ot...

  • EPSS 0.05%
  • Veröffentlicht 14.07.2025 05:39:07
  • Zuletzt bearbeitet 15.07.2025 13:14:24

A stored Cross-Site Scripting (XSS) vulnerability exists in the Access Control of ADM, the issue allows an attacker to inject malicious scripts into the folder name field while creating a new shared folder. These scripts are not properly sanitized an...

  • EPSS 0.02%
  • Veröffentlicht 09.07.2025 08:31:02
  • Zuletzt bearbeitet 10.07.2025 13:17:30

A security bypass vulnerability allows exploitation via Reverse Tabnabbing, a type of phishing attack where attackers can manipulate the content of the original tab, leading to credential theft and other security risks. This issue affects DataSync Ce...

  • EPSS 0.03%
  • Veröffentlicht 09.07.2025 07:15:24
  • Zuletzt bearbeitet 10.07.2025 13:17:30

An improper Input Validation vulnerability allows injecting arbitrary values of the NAS configuration file in ASUSTOR ADM. This could potentially lead to system misconfiguration and break the format of the configuation file, causing the NAS to exhibi...

  • EPSS 0.3%
  • Veröffentlicht 31.05.2023 10:15:09
  • Zuletzt bearbeitet 21.11.2024 07:59:32

EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and be...

  • EPSS 0.17%
  • Veröffentlicht 17.05.2023 07:15:08
  • Zuletzt bearbeitet 21.11.2024 07:58:44

A Cross-Site Scripting(XSS) vulnerability was found on ADM, LooksGood and SoundsGood Apps. An attacker can exploit this vulnerability to inject malicious scripts into the target applications to access any cookies or sensitive information retained by ...

  • EPSS 0.31%
  • Veröffentlicht 17.04.2023 07:15:08
  • Zuletzt bearbeitet 21.11.2024 08:00:52

A stack-based buffer overflow vulnerability was found in the ASUSTOR Data Master (ADM) due to the lack of data size validation. An attacker can exploit this vulnerability to execute arbitrary code. Affected ADM versions include: 4.0.6.REG2, 4.1.0 and...