Junglewise Threat Intelligence

CVE-2026-67244: ASUSTOR ADM format string vulnerability in Notification OAuth settings

CVE-2026-67244 · Severity: info · CVSS 8.6 · Published 2026-07-30

Technologies: ASUSTOR ADM. Vendors: ASUSTOR.

Executive brief

ASUSTOR Data Master (ADM), the operating system for ASUSTOR NAS devices, contains a security vulnerability in its notification settings. An administrator with existing access to the system can exploit this flaw to crash the device or potentially view sensitive information stored in the system's memory. This could lead to service interruptions or the exposure of internal system data.

Technical details

A format string vulnerability (CWE-134) exists in the Notification OAuth settings of ASUSTOR ADM. The flaw is caused by the unsafe processing of user-controlled notification configuration input through a format string operation. An authenticated attacker with administrative privileges can provide specially crafted input to trigger the vulnerability. Successful exploitation can lead to the disclosure of sensitive memory contents or a denial of service (DoS) condition by crashing the affected component. The vulnerability impacts ADM versions 4.1.0 through 4.3.3.RUN1 and 5.0.0 through 5.1.3.RI81.

Affected products

  • ASUSTOR ADM 4.1.0 - 4.3.3.RUN1, 5.0.0 - 5.1.3.RI81

Timeline

  • 2026-07-30: advisory

References

Related threats