Asustor

Data Master

45 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 30.07.2026 03:48:04
  • Zuletzt bearbeitet 04.08.2026 14:05:45

A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-controlled input is not properly validated before being decoded and copied into a fixed-size stack buffer. An authenticated a...

  • EPSS 0.3%
  • Veröffentlicht 30.07.2026 03:42:58
  • Zuletzt bearbeitet 04.08.2026 14:06:15

A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled disk serial input is not sufficiently validated before being used to construct the path of an IHM log database file. An authenti...

  • EPSS 0.31%
  • Veröffentlicht 30.07.2026 03:33:52
  • Zuletzt bearbeitet 04.08.2026 14:06:43

A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is not sufficiently validated before being used for file access. An authenticated attacker can exploit t...

  • EPSS 0.22%
  • Veröffentlicht 30.07.2026 03:29:03
  • Zuletzt bearbeitet 04.08.2026 14:07:07

A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is not sufficiently validated before being used to construct the upload destination path. An authenticated...

  • EPSS 0.28%
  • Veröffentlicht 30.07.2026 03:04:16
  • Zuletzt bearbeitet 04.08.2026 14:07:36

A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-controlled notification configuration input may be processed through an unsafe format string operation. An authenticated administ...

  • EPSS 0.27%
  • Veröffentlicht 30.07.2026 02:59:08
  • Zuletzt bearbeitet 04.08.2026 14:16:14

A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsync backup configuration or log data may be processed through an unsafe format string operation. An authenticated attacker can ...

  • EPSS 0.27%
  • Veröffentlicht 30.07.2026 02:54:45
  • Zuletzt bearbeitet 04.08.2026 14:17:56

A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be included in an error response and processed through an unsafe format string operation. An authenticated atta...

  • EPSS 0.27%
  • Veröffentlicht 30.07.2026 02:44:33
  • Zuletzt bearbeitet 04.08.2026 14:18:10

A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration data may be written into a task log and later processed through an unsafe format string operation. An a...

  • EPSS 1.45%
  • Veröffentlicht 20.04.2026 06:54:42
  • Zuletzt bearbeitet 30.04.2026 13:16:05

A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary code on the underlying operating system. This occurs ...

  • EPSS 0.47%
  • Veröffentlicht 20.04.2026 06:34:27
  • Zuletzt bearbeitet 22.04.2026 14:43:12

A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing user-controlled data directly to printf(). Due to the lack of PIE and Stack Canary protections, an aut...