Junglewise Threat Intelligence

CVE-2026-18187: ASUSTOR ADM format string vulnerability in Internal Backup

CVE-2026-18187 · Severity: info · CVSS 7.1 · Published 2026-07-30

Technologies: ASUSTOR ADM. Vendors: ASUSTOR.

Executive brief

ASUSTOR Data Master (ADM), the operating system used for ASUSTOR network-attached storage (NAS) devices, contains a security vulnerability in its Internal Backup feature. An authorized user can provide specially crafted input that causes the system to crash or potentially leak sensitive information from the device's memory. This could lead to a disruption of backup services or unauthorized access to technical data stored in the system's memory.

Technical details

A format string vulnerability (CWE-134) exists in the Internal Backup component of ASUSTOR ADM. The flaw occurs when user-controlled task input is included in an error response and subsequently processed through an unsafe format string operation within a CGI process. An authenticated attacker with network access can exploit this by submitting malicious input to trigger the vulnerability. Successful exploitation can lead to the disclosure of sensitive memory information or a denial of service (DoS) by crashing the affected CGI process. The vulnerability affects ADM versions 4.1.0 through 4.3.3.RUN1 and 5.0.0 through 5.1.3.RI81.

Affected products

  • ASUSTOR ADM 4.1.0 through 4.3.3.RUN1, 5.0.0 through 5.1.3.RI81

Timeline

  • 2026-07-30: advisory

References

Related threats