CVEs we hold for Asus
Records whose assigning authority named Asus as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-67248A stack-based buffer overflow vulnerability was found in the File Explorer on the ADMASUSTOR Inc. ADM
CVE-2026-67247A path traversal vulnerability was found in the IHM Log handling of ADMASUSTOR Inc. ADM
CVE-2026-67246A path traversal vulnerability was found in the Wallpaper component of ADMASUSTOR Inc. ADM
CVE-2026-67245A path traversal vulnerability was found in the VPN Clients on the ADMASUSTOR Inc. ADM
CVE-2026-67244A format string vulnerability was found in the Notification OAuth settings of ADMASUSTOR Inc. ADM
CVE-2026-6644A command injection vulnerability was found in the PPTP VPN Clients on the ADMASUSTOR Inc. ADM
CVE-2026-6643A stack-based buffer overflow vulnerability in the VPN Clients on the ADMASUSTOR Inc. ADM
CVE-2026-3100An improper certificate validation vulnerability was found in the FTP Backup on the ADM.ASUSTOR ADM
CVE-2026-24936An improper input validation vulnerability was found in ADM while joining a AD Domain.ASUSTOR ADM
CVE-2026-24935An improper certificate validation vulnerability was found in a third-party NAT traversal module.ASUSTOR ADM
CVE-2026-24934An improper certificate validation vulnerability was found in ADM while querying an external server for the device's…ASUSTOR ADM
CVE-2026-24933An improper certificate validation vulnerability was found in ADM while sending HTTPS requests to the server.ASUSTOR ADM
CVE-2026-24932An improper certificate validation vulnerability was found in ADM while updating the DDNS settings.ASUSTOR ADM
CVE-2026-18759An improper authentication and path traversal vulnerability exists in ASUSTOR Backup Plan and ASUSTOR EZ Sync.ASUSTOR Inc. AES
CVE-2026-18188A format string vulnerability was found in the Rsync Backup on the ADMASUSTOR Inc. ADM
CVE-2026-18187A format string vulnerability was found in the Internal Backup on the ADMASUSTOR Inc. ADM
CVE-2026-18186A stored format string vulnerability was found in the FTP Backup on the ADMASUSTOR Inc. ADM
CVE-2025-8070Windows service registered with an unquoted ImagePath vulnerability in the system registryASUSTOR ABP and AES
CVE-2025-7699An improper access control vulnerability was found in the EZ Sync Manager of ADMASUSTOR ADM
CVE-2025-7618A stored Cross-Site Scripting (XSS) vulnerability exists in the File Explorer and Text Editor of ADMASUSTOR ADM
CVE-2025-7380A stored Cross-Site Scripting (XSS) vulnerability exists in the Access Control of ADMASUSTOR ADM
CVE-2025-7379A security bypass vulnerability was found in DataSync Center installed on ADMASUSTOR ADM
CVE-2025-7378An improper input validation vulnerability was found on manipulating configuration of ADMASUSTOR ADM
CVE-2025-13053A missing encryption of sensitive data vulnerability was found in the UPS settings of ADMASUSTOR ADM
CVE-2025-13052An improper certificates validation vulnerability was found in the Notification settings of ADMASUSTOR ADM
CVE-2025-13051Windows service used an uncontrolled search path element will cause unauthorized code execution with localsystem…ASUSTOR ABP and AES
CVE-2023-35720ASUS RT-AX92U lighttpd mod_webdav.so SQL Injection Information Disclosure VulnerabilityASUS RT-AX92U
CVE-2022-38699ASUS Armoury Crate Service - Arbitrary File Creation via Elevation of Privilege FlawASUS Armoury Crate Service
CVE-2022-22262ASUS Armoury Crate & Aura Creator Installer之ROG Live Service - Improper Link Resolution Before File AccessASUS Armoury Crate & Aura Creator Installer (ROG Live…
CVE-2021-41289ASUS P453UJ - Improper Restriction of Operations within the Bounds of a Memory BufferASUS P453UJ BIOS
CVE-2021-37910ASUS GT-AXE11000, RT-AX3000, RT-AX55, RT-AX58U, TUF-AX3000 - Improper AuthenticationASUS TUF-AX3000
CVE-2021-28209ASUS BMC's firmware: path traversal - Delete video file functionASUS BMC firmware for Z11PR-D16
CVE-2021-28208ASUS BMC's firmware: path traversal - Get video file functionASUS BMC firmware for Z11PR-D16
CVE-2021-28207ASUS BMC's firmware: path traversal - Get Help file functionASUS BMC firmware for Z11PR-D16
CVE-2021-28206ASUS BMC's firmware: path traversal - Record video file functionASUS BMC firmware for Z11PR-D16
CVE-2021-28205ASUS BMC's firmware: path traversal - Delete SOL video file functionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28204ASUS BMC's firmware: command injection - Modify user’s information functionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28203ASUS BMC's firmware: command injection - Web Set Media Image functionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28202ASUS BMC's firmware: buffer overflow - Service configuration-2 functionASUS BMC firmware for Z11PR-D16
CVE-2021-28201ASUS BMC's firmware: buffer overflow - Service configuration-1 functionASUS BMC firmware for Z11PR-D16
CVE-2021-28200ASUS BMC's firmware: buffer overflow - CD media configuration functionASUS BMC firmware for Z11PR-D16
CVE-2021-28199ASUS BMC's firmware: buffer overflow - Modify user’s information functionASUS BMC firmware for Z11PR-D16
CVE-2021-28198ASUS BMC's firmware: buffer overflow - Firmware protocol configurationASUS BMC firmware for Z11PR-D16
CVE-2021-28197ASUS BMC's firmware: buffer overflow - Active Directory configuration functionASUS BMC firmware for Z11PR-D16
CVE-2021-28196ASUS BMC's firmware: buffer overflow - Generate SSL certificate functionASUS BMC firmware for Z11PR-D16
CVE-2021-28195ASUS BMC's firmware: buffer overflow - Radius configuration functionASUS BMC firmware for Z11PR-D16
CVE-2021-28194ASUS BMC's firmware: buffer overflow - Remote image configuration settingASUS BMC firmware for Z11PR-D16
CVE-2021-28193ASUS BMC's firmware: buffer overflow - SMTP configuration functionASUS BMC firmware for Z11PR-D16
CVE-2021-28192ASUS BMC's firmware: buffer overflow - Remote video storage functionASUS BMC firmware for Z11PR-D16
CVE-2021-28191ASUS BMC's firmware: buffer overflow - Firmware update functionASUS BMC firmware for Z11PR-D16
CVE-2021-28190ASUS BMC's firmware: buffer overflow - Generate new certificate functionASUS BMC firmware for Z11PR-D16
CVE-2021-28189ASUS BMC's firmware: buffer overflow - SMTP configuration functionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28188ASUS BMC's firmware: buffer overflow - Modify user’s information functionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28187ASUS BMC's firmware: buffer overflow - Generate new SSL certificateASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28186ASUS BMC's firmware: buffer overflow - ActiveX configuration-2 acquisitionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28185ASUS BMC's firmware: buffer overflow - ActiveX configuration-1 acquisitionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28184ASUS BMC's firmware: buffer overflow - Active Directory configuration functionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28183ASUS BMC's firmware: buffer overflow - Web License configuration settingASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28182ASUS BMC's firmware: buffer overflow - Web Service configuration functionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28181ASUS BMC's firmware: buffer overflow - Remote video configuration settingASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28180ASUS BMC's firmware: buffer overflow - Audit log configuration settingASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28179ASUS BMC's firmware: buffer overflow - Media support configuration settingASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28178ASUS BMC's firmware: buffer overflow - UEFI configuration functionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28177ASUS BMC's firmware: buffer overflow - LDAP configuration functionASUS BMC firmware for Z10PE-D16 WS
200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.