We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-7379

A security bypass vulnerability was found in DataSync Center installed on ADM



Description

A security bypass vulnerability allows exploitation via Reverse Tabnabbing, a type of phishing attack where attackers can manipulate the content of the original tab, leading to credential theft and other security risks. This issue affects DataSync Center: from 1.1.0 before 1.1.0.r207, and from 1.2.0 before 1.2.0.r206.

Reserved 2025-07-09 | Published 2025-07-09 | Updated 2025-07-09 | Assigner ASUSTOR1


MEDIUM: 5.2CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H

Problem types

CWE-352 Cross-Site Request Forgery (CSRF)

Product status

Default status
unaffected

1.1.0 before 1.1.0.r207
affected

1.2.0 before 1.2.0.r206
affected

References

www.asustor.com/security/security_advisory_detail?id=42 vendor-advisory

cve.org (CVE-2025-7379)

nvd.nist.gov (CVE-2025-7379)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-7379

Support options

Helpdesk Chat, Email, Knowledgebase