CVE-2025-7618
- EPSS 0.06%
- Veröffentlicht 14.07.2025 10:15:10
- Zuletzt bearbeitet 15.07.2025 13:14:24
A stored Cross-Site Scripting (XSS) vulnerability vulnerability was found in the File Explorer and Text Editor of ADM. An attacker could exploit this vulnerability to inject malicious scripts into the applications, which may then access cookies or ot...
CVE-2025-7380
- EPSS 0.06%
- Veröffentlicht 14.07.2025 05:39:07
- Zuletzt bearbeitet 15.07.2025 13:14:24
A stored Cross-Site Scripting (XSS) vulnerability exists in the Access Control of ADM, the issue allows an attacker to inject malicious scripts into the folder name field while creating a new shared folder. These scripts are not properly sanitized an...
CVE-2025-7379
- EPSS 0.02%
- Veröffentlicht 09.07.2025 08:31:02
- Zuletzt bearbeitet 10.07.2025 13:17:30
A security bypass vulnerability allows exploitation via Reverse Tabnabbing, a type of phishing attack where attackers can manipulate the content of the original tab, leading to credential theft and other security risks. This issue affects DataSync Ce...
- EPSS 0.03%
- Veröffentlicht 09.07.2025 07:15:24
- Zuletzt bearbeitet 10.07.2025 13:17:30
An improper Input Validation vulnerability allows injecting arbitrary values of the NAS configuration file in ASUSTOR ADM. This could potentially lead to system misconfiguration and break the format of the configuation file, causing the NAS to exhibi...
- EPSS 0.4%
- Veröffentlicht 31.05.2023 10:15:09
- Zuletzt bearbeitet 21.11.2024 07:59:32
EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and be...
CVE-2023-2509
- EPSS 0.21%
- Veröffentlicht 17.05.2023 07:15:08
- Zuletzt bearbeitet 21.11.2024 07:58:44
A Cross-Site Scripting(XSS) vulnerability was found on ADM, LooksGood and SoundsGood Apps. An attacker can exploit this vulnerability to inject malicious scripts into the target applications to access any cookies or sensitive information retained by ...
CVE-2023-30770
- EPSS 0.47%
- Veröffentlicht 17.04.2023 07:15:08
- Zuletzt bearbeitet 21.11.2024 08:00:52
A stack-based buffer overflow vulnerability was found in the ASUSTOR Data Master (ADM) due to the lack of data size validation. An attacker can exploit this vulnerability to execute arbitrary code. Affected ADM versions include: 4.0.6.REG2, 4.1.0 and...
CVE-2022-37398
- EPSS 0.52%
- Veröffentlicht 05.08.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:14:55
A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit this vulnerability to run arbitrary code. Affected ADM versions include: 3.5.9.RUE3 and below, 4.0.5.R...
CVE-2018-11510
- EPSS 89.36%
- Veröffentlicht 28.06.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:31
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by embedding OS commands in the 'script' parameter.