← Back

Data Master

data_master

Vendor: Asustor • 45 CVEs

CVEs (45)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Asustor
1Data Master
Nov 21, 2024
Aug 27, 2018
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system when providing the full path to loginimage.cgi.
1Asustor
1Data Master
Nov 21, 2024
Aug 27, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full path. For example, /home/admin/.ash_history.
1Asustor
1Data Master
Nov 21, 2024
Aug 27, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi.
1Asustor
1Data Master
Nov 21, 2024
Aug 27, 2018
N/A· v4
6.5 MEDIUM· v3
8.5 HIGH· v2
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a path traversal vulnerability in wallpaper.cgi.
1Asustor
1Data Master
Nov 21, 2024
Aug 27, 2018
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path traversal vulnerability. This could lead to code execution if the "Web Server"...Show more
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path traversal vulnerability. This could lead to code execution if the "Web Server" feature is enabled.Show less