CVE-2026-3179Disclosure(asustor / data_master)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch asustor data_master systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames containing path traversal sequences, causing the client to write files outside the intended backup directory. A path traversal vulnerability may allow an attacker to overwrite arbitrary files on the system and potentially achieve privilege escalation or remote code execution. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.2.RE51.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • data_master

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 5 mentions (2026-02-25); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
data_master

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-02-25: 5Mentions · 2026-02-26: 1Mentions · 2026-03-02: 1Patch / Workaround · 2026-02-25: 2Technical Details · 2026-02-25: 5Technical Details · 2026-02-26: 1Technical Details · 2026-03-02: 102-2502-2603-02
Signal classification2 categories
Disclosure
571.4%
Patch
228.6%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-255
Disclosure3Patch2
2026-02-261
Disclosure1
2026-03-021
Disclosure1
Full discourse7 posts
  • Gray Hats@the_yellow_fall
    Patch

    ASUSTOR patches a critical 9.2 severity flaw (CVE-2026-3179) and a MitM vulnerability in ADM's FTP Backup. Update to version 5.1.2.REO1 now to secure your data. #ASUSTOR #NAS #CyberSecurity #InfoSec #DataBackup #Vulnerability #PatchNow #StorageSecurity https://securityonline.info/critical-9-2-severity-path-traversal-flaw-compromises-asustor-ftp-backups/

    Post summary

    ASUSTOR has released a patch (v5.1.2.REO1) for the critical CVE‑2026‑3179 path‑traversal flaw and MitM vulnerability in ADM’s FTP Backup, urging users to update to mitigate the risk.

    00001280
    10.4K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3179 (CVSS:9.2, HIGH) is Analyzed. The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listi..https://nvd.nist.gov/vuln/detail/CVE-2026-3179 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-3179, a high‑severity FTP backup sanitization flaw with CVSS 9.2, but provides no PoC, exploit, or patch details.

    0000035
    173 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3179 - High The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames containing ... https://www.thehackerwire.com/vulnerability/CVE-2026-3179/ https://t.co/QpCxPpQJUu

    Post summary

    The post announces CVE-2026-3179, a high‑severity flaw in ADM’s FTP Backup that fails to sanitize filenames from FTP server directory listings, potentially allowing attackers to craft malicious filenames.

    0000050
    115 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3179 Path Traversal in ADM FTP Backup Enabling Arbitrary File Overwrite https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3179

    Post summary

    A path traversal vulnerability in ADM FTP Backup allows arbitrary file overwrite, as disclosed in the linked vulnerability details.

    0000031
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3179 The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can cra… https://www.cve.org/CVERecord?id=CVE-2026-3179

    Post summary

    The text discloses a directory‑listing sanitization flaw in the FTP Backup feature of ADM, which could be exploited by a malicious FTP server or MITM attacker.

    0000096
    56.6K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: ASUSTOR ADM (4.1.0 – 5.1.2.RE51) hit by path traversal flaw — no auth needed! Attackers can overwrite files & escalate privileges. Disable FTP Backup or restrict access ASAP. Details: https://radar.offseq.com/threat/cve-2026-3179-cwe-22-improper-limitation-of-a-pat... https://t.co/3aJPWNWpJC

    Post summary

    ASUSTOR ADM path traversal flaw allows unauthenticated attackers to overwrite files and elevate privileges; disabling FTP backup or restricting access is advised while awaiting vendor patch.

    0000040
    270 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3179: CRITICAL] Warning: FTP Backup vulnerability in ADM versions 4.1.0-4.3.3.ROF1 and 5.0.0-5.1.2.RE51 allows remote attackers to overwrite files and achieve privilege escalation. #CyberSecurity#cve,CVE-2026-3179,#cybersecurity https://cvefind.com/CVE-2026-3179

    Post summary

    A critical FTP backup vulnerability in specific ADM versions allows remote attackers to overwrite files and gain privilege escalation; no PoC, exploit, or patch is mentioned.

    0000078
    584 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSasustordata_master---

Explore more