Data Master
Vendor:
First CVE: Aug 27, 2018 · Active for 7 years
37
Total CVEs
More Total CVEs than 97% of tracked products
9.3
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Data Master over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 27, 2018
7 years ago
Most Recent CVE
Apr 20, 2026
97 days ago
CVE Severity & Scoring
Data Master37 CVEs
46%
38%
11%
All CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (5.4%)
Network35 (94.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (75.7%)
High9 (24.3%)
Unknown0 (0.0%)
User Interaction
None32 (86.5%)
Unknown0 (0.0%)
Required5 (13.5%)
Privileges Required
Low19 (51.4%)
High1 (2.7%)
None17 (45.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-6644CRITICAL A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and e | Apr 20, 2026 | 9.1 | 34 | NO | NO |
CVE-2026-6643CRITICAL A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing user-controlled data directly to | Apr 20, 2026 | 9.9 | 32 | NO | NO |
CVE-2018-12313CRITICAL OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity" URL parameter. | Dec 4, 2018 | 9.8 | 32 | NO | NO |
CVE-2026-3179HIGH The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames | Feb 25, 2026 | 8.1 | 29 | NO | NO |
CVE-2026-24936CRITICAL When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI program allowing an unauthenticated | Feb 3, 2026 | 9.8 | 29 | NO | NO |
CVE-2018-12317HIGH OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" POST parameter. | Dec 4, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-12316HIGH OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST parameter. | Dec 4, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-12312HIGH OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "secret_key" URL parameter. | Dec 4, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-12307HIGH OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "name" POST parameter. | Dec 4, 2018 | 8.8 | 27 | NO | NO |
CVE-2023-2910HIGH Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauth | Aug 17, 2023 | 8.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (37 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (37 CVEs).
Media Mentions
Signals from CVEs in this product scope (37 CVEs).
Top CNAs Publishing CVEs For Data Master
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.1.1 | 15 | 7.6 | 1.9% | 0 | 0 |