CVE-2022-37398 is a critical stack-based buffer overflow vulnerability in ASUSTOR ADM, affecting versions 3.5.9.RUE3 and below, 4.0.5.RVI1 and below, and 4.1.0.RJD1 and below. This flaw, stemming from insufficient data size validation in WebDAV, allows an authenticated remote attacker to execute arbitrary code with a CVSS score of 8.8 (High). While the vulnerability is severe, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in CISA's KEV catalog. Community discussion and media coverage are minimal, suggesting low current public awareness or active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.5, <= 3.5.9.RUE3CPE match | cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:* | ||
>= 4.0, <= 4.0.5.RVI1CPE match | cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:* | ||
>= 4.1, <= 4.1.0.RJD1CPE match | cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:* | ||
>= 3.5.0, <= 3.5.9.rue3CPE matchmatch criteria | cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:* | ||
>= 4.0.0, <= 4.0.5.rvi1CPE matchmatch criteria | cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.