ASUSTOR, Inc.
First CVE: Aug 5, 2022Active for: 4 years
28
CVEs Published
More CVEs Published than 47% of tracked CNAs
7.0
Avg CVEs / Year
More Avg CVEs / Year than 42% of tracked CNAs
7.1
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by ASUSTOR, Inc. as a CNA, 92.9% affect products that ASUSTOR, Inc. develops as a vendor.
92.9%
Self-reported: 26Third-party: 2
Of all the CVEs published that affect products developed by ASUSTOR, Inc., 44.1% are self-published by ASUSTOR, Inc. as a CNA.
44.1%
55.9%
Self-published: 26Published by other CNAs: 33
Trends Over Time
The number and severity of CVEs published by ASUSTOR, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 5, 2022
3 years ago
Most Recent CVE
Apr 20, 2026
95 days ago
Top CVEs
All CVEs published by ASUSTOR, Inc. as a CNA, regardless of affected vendor or product.
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-6644CRITICAL A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and e | Apr 20, 2026 | 9.1 | 34 | NO | NO |
CVE-2026-6643CRITICAL A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing user-controlled data directly to | Apr 20, 2026 | 9.9 | 32 | NO | NO |
CVE-2025-13051CRITICAL When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replace or plant a DLL with the same name as one loaded by the ser | Nov 19, 2025 | 9.3 | 31 | NO | NO |
CVE-2023-30770CRITICAL A stack-based buffer overflow vulnerability was found in the ASUSTOR Data Master (ADM) due to the lack of data size validation. An attacker can exploit this vulnerability to execut | Apr 17, 2023 | 9.8 | 30 | NO | NO |
CVE-2026-3179HIGH The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames | Feb 25, 2026 | 8.1 | 29 | NO | NO |
CVE-2026-24936CRITICAL When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI program allowing an unauthenticated | Feb 3, 2026 | 9.8 | 29 | NO | NO |
CVE-2023-2909CRITICAL EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions inc | May 31, 2023 | 10.0 | 29 | NO | NO |
CVE-2025-8070CRITICAL The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allows a local attacker to execute arbitrary code by placing a ma | Jul 23, 2025 | 9.2 | 26 | NO | NO |
CVE-2022-37398HIGH A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit this vulnerability to run arbitr | Aug 5, 2022 | 8.8 | 26 | NO | NO |
CVE-2023-2910HIGH Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauth | Aug 17, 2023 | 8.8 | 25 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA28 CVEs
43%
25%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (17.9%)
Network23 (82.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (67.9%)
High9 (32.1%)
Unknown0 (0.0%)
User Interaction
None22 (78.6%)
Unknown0 (0.0%)
Required2 (7.1%)
Privileges Required
Low12 (42.9%)
High2 (7.1%)
None14 (50.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (28 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by ASUSTOR, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by ASUSTOR, Inc. as a CNA — matched by CVE ID, not by organization name.