Junglewise Threat Intelligence

CVE-2026-67247: ASUSTOR ADM path traversal in IHM Log handling

CVE-2026-67247 · Severity: info · CVSS 7.1 · Published 2026-07-30

Technologies: ASUSTOR ADM. Vendors: ASUSTOR.

Executive brief

A security vulnerability has been identified in ASUSTOR Data Master (ADM), the operating system used by ASUSTOR network-attached storage (NAS) devices. An authenticated user could exploit a flaw in how the system handles disk information to access files or databases they should not be able to see. This could lead to the unauthorized exposure of sensitive system logs or internal configuration data.

Technical details

A path traversal vulnerability (CWE-22) exists in the IHM Log handling component of ASUSTOR ADM. The issue stems from insufficient validation of user-controlled disk serial input, which is subsequently used to construct the file path for IHM log databases. An authenticated attacker with network access can provide a specially crafted disk serial string containing traversal sequences (e.g., ../) to force the application to access or read files outside of the intended directory. This vulnerability affects ADM versions 4.1.0 through 4.3.3.RUN1 and 5.0.0 through 5.1.3.RI81.

Affected products

  • ASUSTOR ADM 4.1.0 through 4.3.3.RUN1, 5.0.0 through 5.1.3.RI81

Timeline

  • 2026-07-30: advisory: Advisory published by ASUSTOR and NVD.

References

Related threats