📦 Data Master

by Asustor

🔍 What is Data Master?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-24936

CRITICAL CVSS 9.8 Feb 3, 2026

An unauthenticated remote attacker can write arbitrary data to any file on Asustor ADM systems when a specific function is enabled during AD Domain joining. This allows complete system compromise by o...

CVE-2026-3179

HIGH CVSS 8.1 Feb 25, 2026

This path traversal vulnerability in ASUSTOR ADM FTP Backup allows attackers to access files outside the intended directory by manipulating file paths. It affects ASUSTOR NAS devices running ADM versi...

CVE-2023-4475

HIGH CVSS 7.5 Aug 22, 2023

An arbitrary file movement vulnerability in ASUSTOR Data Master (ADM) allows attackers to exploit the file renaming feature to move files to unintended directories. This affects ADM versions 4.0.6.RIS...

CVE-2023-3699

HIGH CVSS 8.7 Aug 22, 2023

An Improper Privilege Management vulnerability in ASUSTOR Data Master (ADM) allows unprivileged local users to modify storage device configurations. This affects ADM versions 4.0.6.RIS1, 4.1.0 and bel...

CVE-2023-2910

HIGH CVSS 8.8 Aug 17, 2023

This CVE describes a command injection vulnerability in ASUSTOR Data Master (ADM) printer service that allows remote unauthorized attackers to execute arbitrary commands on affected systems. The vulne...

CVE-2023-3698

HIGH CVSS 8.5 Aug 17, 2023

This CVE describes a path traversal vulnerability in ASUSTOR ADM printer service that allows remote unauthenticated attackers to delete files outside intended directories. Affected systems include ASU...

CVE-2026-24932

MEDIUM CVSS 5.9 Feb 3, 2026

This vulnerability allows attackers to perform Man-in-the-Middle attacks on DDNS update communications by exploiting improper TLS/SSL certificate validation. Attackers can intercept sensitive informat...

CVE-2026-24933

MEDIUM CVSS 5.9 Feb 3, 2026

This vulnerability allows unauthenticated remote attackers to perform Man-in-the-Middle attacks by intercepting HTTPS communications due to improper SSL/TLS certificate validation. It affects ASUSTOR ...

CVE-2026-24935

MEDIUM CVSS 5.6 Feb 3, 2026

This vulnerability allows a Man-in-the-Middle attacker to intercept or redirect NAT tunnel establishment due to improper SSL/TLS certificate validation in a third-party NAT traversal module. While sub...

CVE-2025-13052

MEDIUM CVSS 5.9 Dec 12, 2025

This vulnerability allows attackers to perform man-in-the-middle attacks against SMTP email notifications in ASUSTOR ADM systems by exploiting improper TLS/SSL certificate validation in msmtp. Sensiti...

CVE-2026-24934

LOW CVSS 3.7 Feb 3, 2026

This CVE describes an insecure DDNS implementation in ASUSTOR ADM software where HTTP connections lack SSL/TLS certificate validation. Unauthenticated attackers can perform MitM attacks to spoof WAN I...

CVE-2025-13053

LOW CVSS 3.7 Dec 12, 2025

This vulnerability allows man-in-the-middle attackers to intercept and potentially modify communications between ASUSTOR NAS devices and UPS servers due to improper TLS certificate validation. Attacke...