Junglewise Threat Intelligence

CVE-2026-18188: ASUSTOR ADM format string vulnerability in Rsync Backup

CVE-2026-18188 · Severity: info · CVSS 7.1 · Published 2026-07-30

Technologies: ASUSTOR ADM. Vendors: ASUSTOR.

Executive brief

ASUSTOR ADM is the operating system used to manage ASUSTOR Network Attached Storage (NAS) devices. A security flaw in the Rsync Backup component allows a logged-in user to crash the backup service or view sensitive system memory information. This could lead to data backup failures or provide an attacker with information needed for further system compromise.

Technical details

A format string vulnerability (CWE-134) exists in the Rsync Backup component of ASUSTOR ADM. The issue stems from the unsafe processing of user-controlled rsync backup configuration or log data through format string operations. An authenticated attacker with network access can exploit this by providing specially crafted input, leading to information disclosure from the process memory or a denial of service (DoS) via a crash of the backup component. The vulnerability affects ADM versions 4.1.0 through 4.3.3.RUN1 and 5.0.0 through 5.1.3.RI81.

Affected products

  • ASUSTOR ADM 4.1.0 through 4.3.3.RUN1, 5.0.0 through 5.1.3.RI81

Timeline

  • 2026-07-30: advisory: NVD publication date
  • 2026-07-29: disclosed: ASUSTOR advisory release

References

Related threats