CVE-2023-2909 Information

Description

EZ Sync service fails to adequately handle user input allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.REG2 4.1.0 and below as well as ADM 4.2.1.RGE2 and below.

Reference

https://www.asustor.com/security/security_advisory_detail?id=25

Share on: