Executive brief
A security vulnerability has been identified in the File Explorer component of ASUSTOR NAS devices. This component is responsible for managing and sharing files stored on the network-attached storage device. An authenticated user could exploit this flaw to crash the file management service, potentially leading to a denial of service or further unauthorized system access, impacting the availability and security of stored data.
Technical details
A stack-based buffer overflow (CWE-121) exists in the File Explorer component of ASUSTOR Data Master (ADM). The vulnerability is caused by a failure to properly validate user-controlled input before it is decoded and copied into a fixed-size stack buffer within a CGI process. An authenticated attacker can exploit this by sending crafted network requests to trigger the overflow. While the primary confirmed impact is a denial of service of the affected CGI process, the lack of runtime protections could potentially allow for broader exploitation. The vulnerability affects ADM versions 4.1.0 through 4.3.3.RUN1 and 5.0.0 through 5.1.3.RI81.
Affected products
- ASUSTOR ADM 4.1.0 through 4.3.3.RUN1, 5.0.0 through 5.1.3.RI81
Timeline
- 2026-07-30: advisory