VYPR

Vendor CVEs

Asustor

All CVEs

69 total · sorted by risk
  • CVE-2018-12310MedDec 4, 2018
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting in the Login page in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript via the System Announcement feature.

  • CVE-2018-11343MedMay 22, 2018
    risk 0.35cvss 5.4epss 0.01

    A persistent cross site scripting vulnerability in playlistmanger.cgi in the ASUSTOR SoundsGood application allows attackers to store cross site scripting payloads via the 'playlist' POST parameter.

  • CVE-2025-7379MedJul 9, 2025
    risk 0.34cvss epss 0.00

    A security bypass vulnerability allows exploitation via Reverse Tabnabbing, a type of phishing attack where attackers can manipulate the content of the original tab, leading to credential theft and other security risks. This issue affects DataSync Center: from 1.1.0 before…

  • CVE-2025-7618MedJul 14, 2025
    risk 0.31cvss epss 0.00

    A stored Cross-Site Scripting (XSS) vulnerability vulnerability was found in the File Explorer and Text Editor of ADM. An attacker could exploit this vulnerability to inject malicious scripts into the applications, which may then access cookies or other sensitive information…

  • CVE-2025-7380MedJul 14, 2025
    risk 0.31cvss epss 0.00

    A stored Cross-Site Scripting (XSS) vulnerability exists in the Access Control of ADM, the issue allows an attacker to inject malicious scripts into the folder name field while creating a new shared folder. These scripts are not properly sanitized and will be executed when the…

  • CVE-2018-15696MedAug 27, 2018
    risk 0.28cvss 4.3epss 0.01

    ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi.

  • CVE-2018-11346MedMay 22, 2018
    risk 0.28cvss 4.3epss 0.01

    An insecure direct object reference vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows the ability to reference the "download_sys_settings" action and then specify files arbitrarily throughout the system via the act parameter.

  • CVE-2018-11342MedMay 22, 2018
    risk 0.28cvss 4.3epss 0.01

    A path traversal vulnerability in fileExplorer.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily specify a path to a file on the system to create folders via the dest_folder parameter.

  • CVE-2026-24934LowFeb 3, 2026
    risk 0.24cvss 3.7epss 0.00

    The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an external server for the device's WAN IP address. An unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) attack to spoof the response, leading the…

  • CVE-2025-13053LowDec 12, 2025
    risk 0.24cvss 3.7epss 0.00

    When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack, which may obtain the…

  • CVE-2026-18759HigAug 4, 2026
    risk 0.00cvss epss 0.00

    The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by AES encryption. Because the encryption key file is readable by standard users and protected using DPAPI. Any authenticated local…

  • CVE-2026-67248HigJul 30, 2026
    risk 0.00cvss 8.8epss 0.00

    A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-controlled input is not properly validated before being decoded and copied into a fixed-size stack buffer. An authenticated attacker can exploit this…

  • CVE-2026-67247MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled disk serial input is not sufficiently validated before being used to construct the path of an IHM log database file. An authenticated attacker can exploit…

  • CVE-2026-67246MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is not sufficiently validated before being used for file access. An authenticated attacker can exploit this issue to access or…

  • CVE-2026-67245HigJul 30, 2026
    risk 0.00cvss 8.1epss 0.00

    A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is not sufficiently validated before being used to construct the upload destination path. An authenticated attacker can exploit this…

  • CVE-2026-67244HigJul 30, 2026
    risk 0.00cvss 7.2epss 0.00

    A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-controlled notification configuration input may be processed through an unsafe format string operation. An authenticated administrator can exploit this issue…

  • CVE-2026-18188HigJul 30, 2026
    risk 0.00cvss 8.1epss 0.00

    A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsync backup configuration or log data may be processed through an unsafe format string operation. An authenticated attacker can exploit this issue to…

  • CVE-2026-18187HigJul 30, 2026
    risk 0.00cvss 8.1epss 0.00

    A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be included in an error response and processed through an unsafe format string operation. An authenticated attacker can exploit this issue…

  • CVE-2026-18186HigJul 30, 2026
    risk 0.00cvss 8.1epss 0.00

    A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration data may be written into a task log and later processed through an unsafe format string operation. An authenticated attacker can…

Page 2 of 2