Asustor

Adm

30 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.47%
  • Veröffentlicht 20.04.2026 06:34:27
  • Zuletzt bearbeitet 22.04.2026 14:43:12

A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing user-controlled data directly to printf(). Due to the lack of PIE and Stack Canary protections, an aut...

  • EPSS 0.49%
  • Veröffentlicht 25.02.2026 06:16:27
  • Zuletzt bearbeitet 26.02.2026 16:32:25

The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames containing path traversal sequences, causing the client to write file...

  • EPSS 0.18%
  • Veröffentlicht 25.02.2026 06:16:26
  • Zuletzt bearbeitet 26.02.2026 16:33:43

The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP server using FTPES/FTPS. An improper validated TLS/SSL certificates allows a remote attacker can intercept network traffic to perform...

  • EPSS 0.78%
  • Veröffentlicht 03.02.2026 04:15:56
  • Zuletzt bearbeitet 19.02.2026 17:39:07

When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI program allowing an unauthenticated remote attacker to write arbitrary data to any file on the system. By ...

  • EPSS 0.14%
  • Veröffentlicht 03.02.2026 03:15:53
  • Zuletzt bearbeitet 19.02.2026 18:19:51

A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While subsequent access to device services requires additional authentication, a Man-in-the-Middle (MitM) attacker can intercept or red...

  • EPSS 0.16%
  • Veröffentlicht 03.02.2026 03:15:53
  • Zuletzt bearbeitet 19.02.2026 18:18:18

The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an external server for the device's WAN IP address. An unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) attack to spoo...

  • EPSS 0.2%
  • Veröffentlicht 03.02.2026 03:15:53
  • Zuletzt bearbeitet 19.02.2026 18:17:38

The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validation vulnerability allows an unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) at...

  • EPSS 0.21%
  • Veröffentlicht 03.02.2026 03:15:53
  • Zuletzt bearbeitet 19.02.2026 18:16:57

The DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Although the connection uses HTTPS, an improper validated TLS/SSL certificates allows a remote attacker can intercept the communication ...

  • EPSS 0.09%
  • Veröffentlicht 12.12.2025 02:46:08
  • Zuletzt bearbeitet 07.10.2026 20:10:01

When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack,...

  • EPSS 0.18%
  • Veröffentlicht 12.12.2025 02:30:35
  • Zuletzt bearbeitet 07.10.2026 20:10:01

When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who can intercept network traffic between the SMTP client and server to execute a man-in-the-middle...