CVEs we hold for Asustor
Records whose assigning authority named Asustor as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-67248A stack-based buffer overflow vulnerability was found in the File Explorer on the ADMASUSTOR Inc. ADM
CVE-2026-67247A path traversal vulnerability was found in the IHM Log handling of ADMASUSTOR Inc. ADM
CVE-2026-67246A path traversal vulnerability was found in the Wallpaper component of ADMASUSTOR Inc. ADM
CVE-2026-67245A path traversal vulnerability was found in the VPN Clients on the ADMASUSTOR Inc. ADM
CVE-2026-67244A format string vulnerability was found in the Notification OAuth settings of ADMASUSTOR Inc. ADM
CVE-2026-6644A command injection vulnerability was found in the PPTP VPN Clients on the ADMASUSTOR Inc. ADM
CVE-2026-6643A stack-based buffer overflow vulnerability in the VPN Clients on the ADMASUSTOR Inc. ADM
CVE-2026-3100An improper certificate validation vulnerability was found in the FTP Backup on the ADM.ASUSTOR ADM
CVE-2026-24936An improper input validation vulnerability was found in ADM while joining a AD Domain.ASUSTOR ADM
CVE-2026-24935An improper certificate validation vulnerability was found in a third-party NAT traversal module.ASUSTOR ADM
CVE-2026-24934An improper certificate validation vulnerability was found in ADM while querying an external server for the device's…ASUSTOR ADM
CVE-2026-24933An improper certificate validation vulnerability was found in ADM while sending HTTPS requests to the server.ASUSTOR ADM
CVE-2026-24932An improper certificate validation vulnerability was found in ADM while updating the DDNS settings.ASUSTOR ADM
CVE-2026-18759An improper authentication and path traversal vulnerability exists in ASUSTOR Backup Plan and ASUSTOR EZ Sync.ASUSTOR Inc. AES
CVE-2026-18188A format string vulnerability was found in the Rsync Backup on the ADMASUSTOR Inc. ADM
CVE-2026-18187A format string vulnerability was found in the Internal Backup on the ADMASUSTOR Inc. ADM
CVE-2026-18186A stored format string vulnerability was found in the FTP Backup on the ADMASUSTOR Inc. ADM
CVE-2025-8070Windows service registered with an unquoted ImagePath vulnerability in the system registryASUSTOR ABP and AES
CVE-2025-7699An improper access control vulnerability was found in the EZ Sync Manager of ADMASUSTOR ADM
CVE-2025-7618A stored Cross-Site Scripting (XSS) vulnerability exists in the File Explorer and Text Editor of ADMASUSTOR ADM
CVE-2025-7380A stored Cross-Site Scripting (XSS) vulnerability exists in the Access Control of ADMASUSTOR ADM
CVE-2025-7379A security bypass vulnerability was found in DataSync Center installed on ADMASUSTOR ADM
CVE-2025-7378An improper input validation vulnerability was found on manipulating configuration of ADMASUSTOR ADM
CVE-2025-13053A missing encryption of sensitive data vulnerability was found in the UPS settings of ADMASUSTOR ADM
CVE-2025-13052An improper certificates validation vulnerability was found in the Notification settings of ADMASUSTOR ADM
CVE-2025-13051Windows service used an uncontrolled search path element will cause unauthorized code execution with localsystem…ASUSTOR ABP and AES
37 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.