CVE-2026-3179 Details
Description
The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames containing path traversal sequences, causing the client to write files outside the intended backup directory. A path traversal vulnerability may allow an attacker to overwrite arbitrary files on the system and potentially achieve privilege escalation or remote code execution. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.2.RE51.
A path traversal vulnerability has been identified in the FTP Backup feature on Asustor's ADM operating system. This vulnerability affects versions 4.1.0 prior to 4.3.3.ROF1 and 5.0.0 prior to 5.1.2.RE51. The issue arises because the FTP Backup does not properly sanitize filenames received from the FTP server when parsing directory listings. As a result, a malicious server or a Man-in-the-Middle (MitM) attacker could craft filenames with path traversal sequences, leading the client to write files outside the designated backup directory. Exploiting this vulnerability could allow an attacker to overwrite arbitrary files on the system, potentially escalating privileges or executing remote code.
Users can upgrade to Asustor ADM 5.1.2.REO1 or above. For versions 4.1, 4.2, and 4.3, the vulnerability is still ongoing.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.asustor.com/security/security_advisory_detail?id=53 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| asustor data master | >= 4.1.0.rhu2, <= 4.3.3.rof1 >= 5.0.0.ra82, < 5.1.2.reo1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 26, 2026 | Initial Analysis | [email protected] |
| Feb 25, 2026 | CVE Modified | [email protected] |
| Feb 25, 2026 | New CVE Received | [email protected] |