← Vulnerability feed

Vulnerability record · CVE-2026-3179 · published 25 February 2026

CVE-2026-3179: Asustor data master path traversal vulnerability

AAsustor · Data Master

The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames containing path traversal sequences, causing the client to write files outside the intended backup directory. A path traversal vulnerability may allow an attacker to overwrite arbitrary files on the system and potentially achieve privilege escalation or remote code execution. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.2.RE51.

9.2 CVSS 4.0 Critical EPSS 0.77% · top 46.2% CWE-22 · Path traversal
9.2CVSS 4.0 base score
0.77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames containing path traversal sequences, causing the client to write files outside the intended backup directory. A path traversal vulnerability may allow an attacker to overwrite arbitrary files on the system and potentially achieve privilege escalation or remote code execution. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.2.RE51.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-3179 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-12313Asustor data master os command injection vulnerabilityOS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity…EPSS 4.4%9.5CVE-2026-24936Asustor data master improper input validation vulnerabilityWhen a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI progr…EPSS 0.81%9.4CVE-2026-6644Asustor data master os command injection vulnerabilityA command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the r…EPSS 2.1%8.9CVE-2026-24932Asustor data master improper certificate validation vulnerabilityThe DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Although the connection uses HTTPS,…EPSS 0.21%8.9CVE-2026-24933Asustor data master improper certificate validation vulnerabilityThe API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validat…EPSS 0.21%8.8CVE-2023-2910Asustor data master command injection vulnerabilityImproper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Ma…EPSS 1.6%8.8CVE-2023-3697Asustor data master path traversal vulnerabilityPrinter service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and …EPSS 0.66%8.8CVE-2018-12307Asustor data master os command injection vulnerabilityOS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "name" POST parameter.EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2026-3179), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.