CVE-2026-3179

The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames containing path traversal sequences, causing the client to write files outside the intended backup directory. A path traversal vulnerability may allow an attacker to overwrite arbitrary files on the system and potentially achieve privilege escalation or remote code execution. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.2.RE51.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:asustor:data_master:*:*:*:*:*:*:*:*
cpe:2.3:o:asustor:data_master:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:43

Type Values Removed Values Added
Summary
  • (es) La copia de seguridad FTP en el ADM no sanea correctamente los nombres de archivo recibidos del servidor FTP al analizar listados de directorios. Un servidor malicioso o atacante MitM puede crear nombres de archivo que contengan secuencias de salto de ruta, haciendo que el cliente escriba archivos fuera del directorio de copia de seguridad previsto. Una vulnerabilidad de salto de ruta puede permitir a un atacante sobrescribir archivos arbitrarios en el sistema y potencialmente lograr escalada de privilegios o ejecución remota de código. Los productos y versiones afectados incluyen: desde ADM 4.1.0 hasta ADM 4.3.3.ROF1, así como desde ADM 5.0.0 hasta ADM 5.1.2.RE51.

26 Feb 2026, 16:32

Type Values Removed Values Added
References () https://www.asustor.com/security/security_advisory_detail?id=53 - () https://www.asustor.com/security/security_advisory_detail?id=53 - Vendor Advisory
First Time Asustor data Master
Asustor
CPE cpe:2.3:o:asustor:data_master:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

25 Feb 2026, 07:16

Type Values Removed Values Added
Summary (en) Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ASUSTOR ADM FTP Backup on Linux, x86, ARM, 64 bit allows Path Traversal.This issue affects ADM: from 4.1.0 through 4.3.3.ROF1, from 5.0.0 through 5.1.2.RE51. (en) The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames containing path traversal sequences, causing the client to write files outside the intended backup directory. A path traversal vulnerability may allow an attacker to overwrite arbitrary files on the system and potentially achieve privilege escalation or remote code execution. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.2.RE51.

25 Feb 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-25 06:16

Updated : 2026-06-17 10:43


NVD link : CVE-2026-3179

Mitre link : CVE-2026-3179

CVE.ORG link : CVE-2026-3179


JSON object : View

Products Affected

asustor

  • data_master
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')