ASUSTOR, Inc.

First CVE: Aug 5, 2022Active for: 4 years
28
CVEs Published
More CVEs Published than 47% of tracked CNAs
7.0
Avg CVEs / Year
More Avg CVEs / Year than 42% of tracked CNAs
7.1
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by ASUSTOR, Inc. as a CNA, 92.9% affect products that ASUSTOR, Inc. develops as a vendor.

92.9%
Self-reported: 26Third-party: 2

Of all the CVEs published that affect products developed by ASUSTOR, Inc., 44.1% are self-published by ASUSTOR, Inc. as a CNA.

44.1%
55.9%
Self-published: 26Published by other CNAs: 33

Trends Over Time

The number and severity of CVEs published by ASUSTOR, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 5, 2022
3 years ago
Most Recent CVE
Apr 20, 2026
95 days ago

Top CVEs

All CVEs published by ASUSTOR, Inc. as a CNA, regardless of affected vendor or product.

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and e
Apr 20, 20269.134NONO
A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing user-controlled data directly to
Apr 20, 20269.932NONO
When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replace or plant a DLL with the same name as one loaded by the ser
Nov 19, 20259.331NONO
A stack-based buffer overflow vulnerability was found in the ASUSTOR Data Master (ADM) due to the lack of data size validation. An attacker can exploit this vulnerability to execut
Apr 17, 20239.830NONO
The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames
Feb 25, 20268.129NONO
When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI program allowing an unauthenticated
Feb 3, 20269.829NONO
EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions inc
May 31, 202310.029NONO
The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allows a local attacker to execute arbitrary code by placing a ma
Jul 23, 20259.226NONO
A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit this vulnerability to run arbitr
Aug 5, 20228.826NONO
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauth
Aug 17, 20238.825NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA28 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local5 (17.9%)
Network23 (82.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (67.9%)
High9 (32.1%)
Unknown0 (0.0%)
User Interaction
None22 (78.6%)
Unknown0 (0.0%)
Required2 (7.1%)
Privileges Required
Low12 (42.9%)
High2 (7.1%)
None14 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by ASUSTOR, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by ASUSTOR, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs