Vulnerabilities > Asustor > High

DATE CVE VULNERABILITY TITLE RISK
2023-08-17 CVE-2023-2910 Command Injection vulnerability in Asustor Data Master
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauthorized users to execute arbitrary commands via unspecified vectors.
network
low complexity
asustor CWE-77
8.8
2023-08-17 CVE-2023-3697 Path Traversal vulnerability in Asustor Data Master
Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and create files.
network
low complexity
asustor CWE-22
8.8
2023-08-17 CVE-2023-3698 Path Traversal vulnerability in Asustor Data Master
Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and delete files.
network
low complexity
asustor CWE-22
8.1
2023-05-31 CVE-2023-2749 Incorrect Default Permissions vulnerability in Asustor Download Center
Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability to gain unauthorized access to sensitive files or directories without appropriate permission restrictions.
network
low complexity
asustor CWE-276
7.5
2020-03-18 CVE-2019-11688 Improper Certificate Validation vulnerability in Asustor Exfat Driver 1.0.0
An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20.
network
asustor CWE-295
8.8
2018-12-04 CVE-2018-12314 Path Traversal vulnerability in Asustor Data Master 3.1.1
Directory Traversal in downloadwallpaper.cgi in ASUSTOR ADM version 3.1.1 allows attackers to download arbitrary files by manipulating the "file" and "folder" URL parameters.
network
low complexity
asustor CWE-22
7.8
2018-08-27 CVE-2018-15695 Path Traversal vulnerability in Asustor Data Master
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a path traversal vulnerability in wallpaper.cgi.
network
low complexity
asustor CWE-22
8.5
2018-08-16 CVE-2018-11511 SQL Injection vulnerability in Asustor Data Master 3.1.0
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI.
network
low complexity
asustor CWE-89
7.5
2018-08-16 CVE-2018-11509 Use of Hard-coded Credentials vulnerability in Asustor Data Master 3.1.0
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository.
network
low complexity
asustor CWE-798
7.5