CVE-2023-2909: Asustor Adm

Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.

EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and below.

Affected products

  • Asustor Adm: from 4.0.0, up to and including 4.0.6.reg2; from 4.1.0, up to and including 4.1.0rlq1; from 4.2.0, up to and including 4.2.1.rge2

Published 2023-05-31. Last modified 2026-06-17.