ASUSTOR kayıtları
asustor üreticisine ait 62 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')15
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')8
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-295 Improper Certificate Validation7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-134 Use of Externally-Controlled Format String4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
62 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
52Planlayın | CVE-2018-11510Kavram kanıtı | The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgasustor · adm · CWE-78 | Kritik9,8 | — | %44,3 | 28 Haz 2018 |
43Planlayın | CVE-2018-11509Kavram kanıtı | ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are instalasustor · asustor data master · CWE-798 | Kritik9,8 | — | %12,6 | 16 Ağu 2018 |
42Planlayın | CVE-2018-11511Kavram kanıtı | The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'aasustor · asustor data master · CWE-89 | Kritik9,8 | — | %11,3 | 16 Ağu 2018 |
40Planlayın | CVE-2018-12313İstismar yok | OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "roasustor · data master · CWE-78 | Kritik9,8 | — | %4,4 | 4 Ara 2018 |
40Planlayın | CVE-2023-2909İstismar yok | A Directory traversal vulnerability was found on EZ Sync service of ADMasustor · adm · CWE-22 | Kritik10,0 | — | %0,7 | 31 May 2023 |
39İzleyin | CVE-2023-30770İstismar yok | A stack-based buffer overflow vulnerability was found in the ADMasustor · adm · CWE-787 | Kritik9,8 | — | %0,6 | 17 Nis 2023 |
38İzleyin | CVE-2026-6644Kavram kanıtı | A command injection vulnerability was found in the PPTP VPN Clients on the ADMasustor · data master · CWE-78 | Kritik9,4 | — | %2,1 | 20 Nis 2026 |
38İzleyin | CVE-2026-24936İstismar yok | An improper input validation vulnerability was found in ADM while joining a AD Domain.asustor · data master · CWE-20 | Kritik9,5 | — | %0,8 | 3 Şub 2026 |
36İzleyin | CVE-2018-12307İstismar yok | OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "name" POST parameasustor · data master · CWE-78 | Yüksek8,8 | — | %3,4 | 4 Ara 2018 |
36İzleyin | CVE-2018-12317İstismar yok | OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" Pasustor · data master · CWE-78 | Yüksek8,8 | — | %3,4 | 4 Ara 2018 |
36İzleyin | CVE-2018-12316İstismar yok | OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST pasustor · data master · CWE-78 | Yüksek8,8 | — | %3,4 | 4 Ara 2018 |
36İzleyin | CVE-2018-12312İstismar yok | OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "secret_key" URL pasustor · data master · CWE-78 | Yüksek8,8 | — | %3,4 | 4 Ara 2018 |
36İzleyin | CVE-2018-11345İstismar yok | An unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data via the Pasustor · as6202t firmware · CWE-434 | Yüksek8,8 | — | %1,9 | 21 May 2018 |
36İzleyin | CVE-2026-3179İstismar yok | A path traversal vulnerability was found in the FTP Backup on the ADM.asustor · data master · CWE-22 | Kritik9,2 | — | %0,8 | 25 Şub 2026 |
35İzleyin | CVE-2023-2910İstismar yok | A Command injection vulnerability was found on Printer service of ADMasustor · data master · CWE-77 | Yüksek8,8 | — | %1,6 | 17 Ağu 2023 |
35İzleyin | CVE-2018-12318İstismar yok | Information disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP password in cleartext.asustor · data master · CWE-200 | Yüksek8,8 | — | %1,1 | 4 Ara 2018 |
35İzleyin | CVE-2022-37398İstismar yok | A stack-based buffer overflow vulnerability was found on ADMasustor · adm · CWE-121 | Yüksek8,8 | — | %0,7 | 5 Ağu 2022 |
35İzleyin | CVE-2023-3697İstismar yok | A Command injection vulnerability was found on Printer service of ADMasustor · data master · CWE-22 | Yüksek8,8 | — | %0,7 | 17 Ağu 2023 |
35İzleyin | CVE-2026-24932İstismar yok | An improper certificate validation vulnerability was found in ADM while updating the DDNS settings.asustor · data master · CWE-295 | Yüksek8,9 | — | %0,2 | 2 Şub 2026 |
35İzleyin | CVE-2026-24933İstismar yok | An improper certificate validation vulnerability was found in ADM while sending HTTPS requests to the server.asustor · data master · CWE-295 | Yüksek8,9 | — | %0,2 | 2 Şub 2026 |
34İzleyin | CVE-2026-6643Kavram kanıtı | A stack-based buffer overflow vulnerability in the VPN Clients on the ADMasustor · data master · CWE-121 | Yüksek8,6 | — | %0,8 | 20 Nis 2026 |
34İzleyin | CVE-2026-67244İstismar yok | A format string vulnerability was found in the Notification OAuth settings of ADMasustor · data master · CWE-134 | Yüksek8,6 | — | %0,5 | 29 Tem 2026 |
34İzleyin | CVE-2026-67248İstismar yok | A stack-based buffer overflow vulnerability was found in the File Explorer on the ADMasustor · data master · CWE-121 | Yüksek8,7 | — | %0,5 | 30 Tem 2026 |
33İzleyin | CVE-2019-11689İstismar yok | An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20.asustor · exfat driver · CWE-78 | Yüksek8,1 | — | %3,2 | 18 Mar 2020 |
33İzleyin | CVE-2026-3100İstismar yok | An improper certificate validation vulnerability was found in the FTP Backup on the ADM.asustor · data master · CWE-295 | Yüksek8,3 | — | %0,3 | 25 Şub 2026 |
- CVE-2018-1151052Planlayın
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cg
KritikCVSS 9,8Kavram kanıtıEPSS %44asustor · adm28 Haz 2018
- CVE-2018-1150943Planlayın
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are instal
KritikCVSS 9,8Kavram kanıtıEPSS %13asustor · asustor data master16 Ağu 2018
- CVE-2018-1151142Planlayın
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'a
KritikCVSS 9,8Kavram kanıtıEPSS %11asustor · asustor data master16 Ağu 2018
- CVE-2018-1231340Planlayın
OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "ro
KritikCVSS 9,8İstismar yokEPSS %4asustor · data master4 Ara 2018
- CVE-2023-290940Planlayın
A Directory traversal vulnerability was found on EZ Sync service of ADM
KritikCVSS 10,0İstismar yokEPSS %1asustor · adm31 May 2023
- CVE-2023-3077039İzleyin
A stack-based buffer overflow vulnerability was found in the ADM
KritikCVSS 9,8İstismar yokEPSS %1asustor · adm17 Nis 2023
- CVE-2026-664438İzleyin
A command injection vulnerability was found in the PPTP VPN Clients on the ADM
KritikCVSS 9,4Kavram kanıtıEPSS %2asustor · data master20 Nis 2026
- CVE-2026-2493638İzleyin
An improper input validation vulnerability was found in ADM while joining a AD Domain.
KritikCVSS 9,5İstismar yokEPSS %1asustor · data master3 Şub 2026
- CVE-2018-1230736İzleyin
OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "name" POST parame
YüksekCVSS 8,8İstismar yokEPSS %3asustor · data master4 Ara 2018
- CVE-2018-1231736İzleyin
OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" P
YüksekCVSS 8,8İstismar yokEPSS %3asustor · data master4 Ara 2018
- CVE-2018-1231636İzleyin
OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST p
YüksekCVSS 8,8İstismar yokEPSS %3asustor · data master4 Ara 2018
- CVE-2018-1231236İzleyin
OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "secret_key" URL p
YüksekCVSS 8,8İstismar yokEPSS %3asustor · data master4 Ara 2018
- CVE-2018-1134536İzleyin
An unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data via the P
YüksekCVSS 8,8İstismar yokEPSS %2asustor · as6202t firmware21 May 2018
- CVE-2026-317936İzleyin
A path traversal vulnerability was found in the FTP Backup on the ADM.
KritikCVSS 9,2İstismar yokEPSS %1asustor · data master25 Şub 2026
- CVE-2023-291035İzleyin
A Command injection vulnerability was found on Printer service of ADM
YüksekCVSS 8,8İstismar yokEPSS %2asustor · data master17 Ağu 2023
- CVE-2018-1231835İzleyin
Information disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP password in cleartext.
YüksekCVSS 8,8İstismar yokEPSS %1asustor · data master4 Ara 2018
- CVE-2022-3739835İzleyin
A stack-based buffer overflow vulnerability was found on ADM
YüksekCVSS 8,8İstismar yokEPSS %1asustor · adm5 Ağu 2022
- CVE-2023-369735İzleyin
A Command injection vulnerability was found on Printer service of ADM
YüksekCVSS 8,8İstismar yokEPSS %1asustor · data master17 Ağu 2023
- CVE-2026-2493235İzleyin
An improper certificate validation vulnerability was found in ADM while updating the DDNS settings.
YüksekCVSS 8,9İstismar yokEPSS %0asustor · data master2 Şub 2026
- CVE-2026-2493335İzleyin
An improper certificate validation vulnerability was found in ADM while sending HTTPS requests to the server.
YüksekCVSS 8,9İstismar yokEPSS %0asustor · data master2 Şub 2026
- CVE-2026-664334İzleyin
A stack-based buffer overflow vulnerability in the VPN Clients on the ADM
YüksekCVSS 8,6Kavram kanıtıEPSS %1asustor · data master20 Nis 2026
- CVE-2026-6724434İzleyin
A format string vulnerability was found in the Notification OAuth settings of ADM
YüksekCVSS 8,6İstismar yokEPSS %0asustor · data master29 Tem 2026
- CVE-2026-6724834İzleyin
A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM
YüksekCVSS 8,7İstismar yokEPSS %0asustor · data master30 Tem 2026
- CVE-2019-1168933İzleyin
An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20.
YüksekCVSS 8,1İstismar yokEPSS %3asustor · exfat driver18 Mar 2020
- CVE-2026-310033İzleyin
An improper certificate validation vulnerability was found in the FTP Backup on the ADM.
YüksekCVSS 8,3İstismar yokEPSS %0asustor · data master25 Şub 2026