ASUSTOR, Inc. manufactures network-attached storage and data management appliances, including the ADM operating system and product lines such as the AS602T and AS6202T, which serve as centralized storage and backup targets in small-to-medium enterprise and departmental environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability reflecting the appeal of networked storage as a high-value target. The exposure recurs through input-handling and authentication-related weakness classes, particularly path traversal, OS command injection, improper certificate validation, cross-site scripting, and exposure of sensitive information, which are typical of web-facing appliance interfaces and administrative protocols. Defenders should prioritize patching for internet-exposed instances and enforce network segmentation around storage access, as these device classes are frequent targets for ransomware staging and lateral movement. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by ASUSTOR, Inc. over time
Of all the CVEs published by ASUSTOR, Inc. as a CNA, 92.9% affect products that ASUSTOR, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by ASUSTOR, Inc., 44.1% are self-published by ASUSTOR, Inc. as a CNA.
Signals from CVEs in this vendor scope (59 CVEs).
59 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11510CRITICAL The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by embedding OS commands in the ' | Jun 28, 2018 | 9.8 | 67 | NO | YES |
CVE-2018-11511CRITICAL The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a phot | Aug 16, 2018 | 9.8 | 56 | NO | YES |
CVE-2018-11509CRITICAL ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may | Aug 16, 2018 | 9.8 | 49 | NO | YES |
CVE-2026-6644CRITICAL A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and e | Apr 20, 2026 | 9.1 | 34 | NO | NO |
CVE-2026-6643CRITICAL A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing user-controlled data directly to | Apr 20, 2026 | 9.9 | 32 | NO | NO |
CVE-2018-12313CRITICAL OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity" URL parameter. | Dec 4, 2018 | 9.8 | 32 | NO | NO |
CVE-2023-30770CRITICAL A stack-based buffer overflow vulnerability was found in the ASUSTOR Data Master (ADM) due to the lack of data size validation. An attacker can exploit this vulnerability to execut | Apr 17, 2023 | 9.8 | 30 | NO | NO |
CVE-2026-3179HIGH The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames | Feb 25, 2026 | 8.1 | 29 | NO | NO |
CVE-2026-24936CRITICAL When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI program allowing an unauthenticated | Feb 3, 2026 | 9.8 | 29 | NO | NO |
CVE-2023-2909CRITICAL EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions inc | May 31, 2023 | 10.0 | 29 | NO | NO |
Signals from CVEs in this vendor scope (59 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by ASUSTOR, Inc..
Media articles that mention a CVE ID that affects a product developed by ASUSTOR, Inc. — matched by CVE ID, not by vendor name.