CVE-2023-2910: Asustor Data Master
High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauthorized users to execute arbitrary commands via unspecified vectors. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.
Affected products
- Asustor Data Master: from 4.0.0.rib4, up to and including 4.0.6.ris1; from 4.1.0.rhu2, before 4.2.3.rk91 (fixed in 4.2.3.rk91)
Published 2023-08-17. Last modified 2026-06-17.