Junglewise Threat Intelligence

CVE-2026-67245: ASUSTOR ADM path traversal in VPN Clients

CVE-2026-67245 · Severity: info · CVSS 7 · Published 2026-07-30

Technologies: ASUSTOR ADM. Vendors: ASUSTOR.

Executive brief

A security vulnerability has been identified in the VPN client component of ASUSTOR Data Master (ADM), the operating system used for ASUSTOR storage devices. An authorized user with high-level privileges could potentially bypass folder restrictions to place files in unauthorized locations on the system. This could lead to unauthorized system changes or disruption of services, though it requires the attacker to already have administrative-level access.

Technical details

A path traversal vulnerability (CWE-22) exists in the VPN Clients component of ASUSTOR ADM. The flaw stems from insufficient validation of user-supplied certificate names before they are used to construct file upload destination paths. An authenticated attacker with high privileges (PR:H) can exploit this by providing a specially crafted certificate name containing traversal sequences (e.g., ../). This allows the attacker to write uploaded certificate files to arbitrary locations on the filesystem, subject to the permissions of the affected process. The vulnerability affects ADM versions 4.1.0 through 4.3.3.RUN1 and 5.0.0 through 5.1.3.RI81.

Affected products

  • ASUSTOR ADM 4.1.0 through 4.3.3.RUN1, 5.0.0 through 5.1.3.RI81

Timeline

  • 2026-07-30: advisory

References

Related threats