Junglewise Threat Intelligence

CVE-2026-67246: ASUSTOR ADM path traversal in Wallpaper component

CVE-2026-67246 · Severity: info · CVSS 6.9 · Published 2026-07-30

Technologies: ASUSTOR ADM. Vendors: ASUSTOR.

Executive brief

ASUSTOR ADM is the operating system used to manage ASUSTOR Network Attached Storage (NAS) devices. A security flaw in the wallpaper management component allows an authorized user to bypass folder restrictions. This could lead to the unauthorized viewing or manipulation of sensitive system files, potentially compromising the privacy and integrity of data stored on the NAS.

Technical details

A path traversal vulnerability (CWE-22) exists in the Wallpaper component of ASUSTOR ADM due to insufficient validation of user-supplied path input. An authenticated attacker with high privileges can provide specially crafted paths (e.g., using dot-dot-slash sequences) to access or modify files on the underlying filesystem that are outside the designated wallpaper directory. The exploit is subject to the permissions of the user account and general filesystem restrictions. The vulnerability affects ADM versions 4.1.0 through 4.3.3.RUN1 and 5.0.0 through 5.1.3.RI81.

Affected products

  • ASUSTOR ADM 4.1.0 - 4.3.3.RUN1, 5.0.0 - 5.1.3.RI81

Timeline

  • 2026-07-30: advisory: ASUSTOR published security advisory AS-2026-019
  • 2026-07-30: disclosed: CVE-2026-67246 published to NVD

References

Related threats