vciy

CVEs we hold for Asustor

Records whose assigning authority named Asustor as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-67248A stack-based buffer overflow vulnerability was found in the File Explorer on the ADMASUSTOR Inc. ADM
CVE-2026-67247A path traversal vulnerability was found in the IHM Log handling of ADMASUSTOR Inc. ADM
CVE-2026-67246A path traversal vulnerability was found in the Wallpaper component of ADMASUSTOR Inc. ADM
CVE-2026-67245A path traversal vulnerability was found in the VPN Clients on the ADMASUSTOR Inc. ADM
CVE-2026-67244A format string vulnerability was found in the Notification OAuth settings of ADMASUSTOR Inc. ADM
CVE-2026-6644A command injection vulnerability was found in the PPTP VPN Clients on the ADMASUSTOR Inc. ADM
CVE-2026-6643A stack-based buffer overflow vulnerability in the VPN Clients on the ADMASUSTOR Inc. ADM
CVE-2026-3179A path traversal vulnerability was found in the FTP Backup on the ADM.ASUSTOR ADM
CVE-2026-3100An improper certificate validation vulnerability was found in the FTP Backup on the ADM.ASUSTOR ADM
CVE-2026-24936An improper input validation vulnerability was found in ADM while joining a AD Domain.ASUSTOR ADM
CVE-2026-24935An improper certificate validation vulnerability was found in a third-party NAT traversal module.ASUSTOR ADM
CVE-2026-24934An improper certificate validation vulnerability was found in ADM while querying an external server for the device's…ASUSTOR ADM
CVE-2026-24933An improper certificate validation vulnerability was found in ADM while sending HTTPS requests to the server.ASUSTOR ADM
CVE-2026-24932An improper certificate validation vulnerability was found in ADM while updating the DDNS settings.ASUSTOR ADM
CVE-2026-18759An improper authentication and path traversal vulnerability exists in ASUSTOR Backup Plan and ASUSTOR EZ Sync.ASUSTOR Inc. AES
CVE-2026-18188A format string vulnerability was found in the Rsync Backup on the ADMASUSTOR Inc. ADM
CVE-2026-18187A format string vulnerability was found in the Internal Backup on the ADMASUSTOR Inc. ADM
CVE-2026-18186A stored format string vulnerability was found in the FTP Backup on the ADMASUSTOR Inc. ADM
CVE-2025-8070Windows service registered with an unquoted ImagePath vulnerability in the system registryASUSTOR ABP and AES
CVE-2025-7699An improper access control vulnerability was found in the EZ Sync Manager of ADMASUSTOR ADM
CVE-2025-7618A stored Cross-Site Scripting (XSS) vulnerability exists in the File Explorer and Text Editor of ADMASUSTOR ADM
CVE-2025-7380A stored Cross-Site Scripting (XSS) vulnerability exists in the Access Control of ADMASUSTOR ADM
CVE-2025-7379A security bypass vulnerability was found in DataSync Center installed on ADMASUSTOR ADM
CVE-2025-7378An improper input validation vulnerability was found on manipulating configuration of ADMASUSTOR ADM
CVE-2025-13053A missing encryption of sensitive data vulnerability was found in the UPS settings of ADMASUSTOR ADM
CVE-2025-13052An improper certificates validation vulnerability was found in the Notification settings of ADMASUSTOR ADM
CVE-2025-13051Windows service used an uncontrolled search path element will cause unauthorized code execution with localsystem…ASUSTOR ABP and AES
CVE-2023-4475An Arbitrary File Movement vulnerability was found on the ADMASUSTOR ADM
CVE-2023-3699An Improper Privilege Management vulnerability was found on the ADMASUSTOR ADM
CVE-2023-3698A Command injection vulnerability was found on Printer service of ADMASUSTOR ADM
CVE-2023-3697A Command injection vulnerability was found on Printer service of ADMASUSTOR ADM
CVE-2023-30770A stack-based buffer overflow vulnerability was found in the ADMASUSTOR ADM
CVE-2023-2910A Command injection vulnerability was found on Printer service of ADMASUSTOR ADM
CVE-2023-2909A Directory traversal vulnerability was found on EZ Sync service of ADMASUSTOR ADM
CVE-2023-2749A Gain Information vulnerability was found on Download Center.ASUSTOR Download Center
CVE-2023-2509A Cross-Site Scripting(XSS) vulnerability was found on ADMASUSTOR SoundsGood
CVE-2022-37398A stack-based buffer overflow vulnerability was found on ADMASUSTOR ADM

37 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.