VYPR

Data Master

by Asustor

CVEs (46)

  • CVE-2026-67246MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is not sufficiently validated before being used for file access. An authenticated attacker can exploit this issue to access or…

  • CVE-2026-67245HigJul 30, 2026
    risk 0.00cvss 8.1epss 0.00

    A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is not sufficiently validated before being used to construct the upload destination path. An authenticated attacker can exploit this…

  • CVE-2026-67244HigJul 30, 2026
    risk 0.00cvss 7.2epss 0.00

    A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-controlled notification configuration input may be processed through an unsafe format string operation. An authenticated administrator can exploit this issue…

  • CVE-2026-18188HigJul 30, 2026
    risk 0.00cvss 8.1epss 0.00

    A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsync backup configuration or log data may be processed through an unsafe format string operation. An authenticated attacker can exploit this issue to…

  • CVE-2026-18187HigJul 30, 2026
    risk 0.00cvss 8.1epss 0.00

    A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be included in an error response and processed through an unsafe format string operation. An authenticated attacker can exploit this issue…

  • CVE-2026-18186HigJul 30, 2026
    risk 0.00cvss 8.1epss 0.00

    A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration data may be written into a task log and later processed through an unsafe format string operation. An authenticated attacker can…

Page 3 of 3