Executive brief
A security vulnerability has been identified in ASUSTOR ADM, the operating system used to manage ASUSTOR network-attached storage (NAS) devices. The flaw exists in the FTP Backup feature, where malicious configuration data can interfere with how the system logs tasks. If exploited, an authorized user could crash the backup service or potentially view sensitive information stored in the system's memory, impacting the reliability of data backups.
Technical details
A stored format string vulnerability (CWE-134) exists in the FTP Backup component of ASUSTOR ADM. The issue stems from the application writing user-controlled backup configuration data into a task log, which is subsequently processed by an unsafe format string operation in a CGI process. An authenticated attacker with network access can exploit this by providing specially crafted configuration strings. Successful exploitation can lead to the disclosure of sensitive memory information or a denial of service (DoS) by crashing the affected CGI process. The vulnerability affects ADM versions 4.1.0 through 4.3.3.RUN1 and 5.0.0 through 5.1.3.RI81.
Affected products
- ASUSTOR ADM 4.1.0 through 4.3.3.RUN1, 5.0.0 through 5.1.3.RI81
Timeline
- 2026-07-30: advisory