Impact
A format string vulnerability exists in the Internal Backup component of the ADM. User‑controlled task input can be included in an error response and processed through an unsafe format string operation. An attacker who authenticates to the system can exploit this flaw to read memory contents or to crash the CGI process, resulting in information disclosure or denial of service.
Affected Systems
ASUSTOR ADM firmware versions 4.1.0 through 4.3.3.RUN1 and 5.0.0 through 5.1.3.RI81 are affected.
Risk and Exploitability
The CVSS base score of 7.1 indicates a moderate to high severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated to access the Internal Backup feature; the flaw allows them to disclose sensitive memory data or crash the CGI process, thereby compromising confidentiality or availability.
OpenCVE Enrichment