Executive brief
ASUSTOR ADM is the operating system used to manage ASUSTOR Network Attached Storage (NAS) devices. A security flaw in the wallpaper management component allows an authorized user to bypass folder restrictions. This could lead to the unauthorized viewing or manipulation of sensitive system files, potentially compromising the privacy and integrity of data stored on the NAS.
Technical details
A path traversal vulnerability (CWE-22) exists in the Wallpaper component of ASUSTOR ADM due to insufficient validation of user-supplied path input. An authenticated attacker with high privileges can provide specially crafted paths (e.g., using dot-dot-slash sequences) to access or modify files on the underlying filesystem that are outside the designated wallpaper directory. The exploit is subject to the permissions of the user account and general filesystem restrictions. The vulnerability affects ADM versions 4.1.0 through 4.3.3.RUN1 and 5.0.0 through 5.1.3.RI81.
Affected products
- ASUSTOR ADM 4.1.0 - 4.3.3.RUN1, 5.0.0 - 5.1.3.RI81
Timeline
- 2026-07-30: advisory: ASUSTOR published security advisory AS-2026-019
- 2026-07-30: disclosed: CVE-2026-67246 published to NVD