Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

ASUSTOR, Inc.

First CVE: May 22, 2018Active for: 8 yearsTotal CVEs: 59
43.9
VTI Score
High

ASUSTOR, Inc. manufactures network-attached storage and data management appliances, including the ADM operating system and product lines such as the AS602T and AS6202T, which serve as centralized storage and backup targets in small-to-medium enterprise and departmental environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability reflecting the appeal of networked storage as a high-value target. The exposure recurs through input-handling and authentication-related weakness classes, particularly path traversal, OS command injection, improper certificate validation, cross-site scripting, and exposure of sensitive information, which are typical of web-facing appliance interfaces and administrative protocols. Defenders should prioritize patching for internet-exposed instances and enforce network segmentation around storage access, as these device classes are frequent targets for ransomware staging and lateral movement. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
59
Total CVEs
More Total CVEs than 99% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by ASUSTOR, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 22, 2018
8 years ago
Most Recent CVE
Apr 20, 2026
95 days ago

Self-Reporting Analysis

Of all the CVEs published by ASUSTOR, Inc. as a CNA, 92.9% affect products that ASUSTOR, Inc. develops as a vendor.

92.9%
Self-reported: 26 (92.9%)
Third-party: 2 (7.1%)

Of all the CVEs published that affect products developed by ASUSTOR, Inc., 44.1% are self-published by ASUSTOR, Inc. as a CNA.

44.1%
55.9%
Self-published: 26 (44.1%)
Other CNAs: 33 (55.9%)

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (59 CVEs).

59 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-11510CRITICAL
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by embedding OS commands in the '
Jun 28, 20189.867NOYES
CVE-2018-11511CRITICAL
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a phot
Aug 16, 20189.856NOYES
CVE-2018-11509CRITICAL
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may
Aug 16, 20189.849NOYES
CVE-2026-6644CRITICAL
A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and e
Apr 20, 20269.134NONO
CVE-2026-6643CRITICAL
A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing user-controlled data directly to
Apr 20, 20269.932NONO
CVE-2018-12313CRITICAL
OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity" URL parameter.
Dec 4, 20189.832NONO
CVE-2023-30770CRITICAL
A stack-based buffer overflow vulnerability was found in the ASUSTOR Data Master (ADM) due to the lack of data size validation. An attacker can exploit this vulnerability to execut
Apr 17, 20239.830NONO
CVE-2026-3179HIGH
The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames
Feb 25, 20268.129NONO
CVE-2026-24936CRITICAL
When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI program allowing an unauthenticated
Feb 3, 20269.829NONO
CVE-2023-2909CRITICAL
EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions inc
May 31, 202310.029NONO
View all 59 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products59 CVEs
44%
37%
15%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (5.1%)
Network56 (94.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low47 (79.7%)
High12 (20.3%)
Unknown0 (0.0%)
User Interaction
None48 (81.4%)
Unknown0 (0.0%)
Required7 (11.9%)
Privileges Required
Low29 (49.2%)
High4 (6.8%)
None26 (44.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (59 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.7% of CVEs· 95th percentile
ExploitDB
3 CVEs
5.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by ASUSTOR, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by ASUSTOR, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For ASUSTOR, Inc.'s Products

View all 3 CNAs →

Top CWEs