Impact
The flaw lies in the Rsync Backup component of ASUSTOR ADM devices, whereby user‑controlled configuration or log data is passed to an unsafe format string operation. An authenticated attacker can exploit this to leak memory contents or trigger a crash, resulting in memory disclosure or denial of service of the affected backup component.
Affected Systems
ASUSTOR Adm devices running firmware versions ADM 4.1.0 through ADM 4.3.3.RUN1 or ADM 5.0.0 through ADM 5.1.3.RI81 are affected.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity, and the very low EPSS score (<1%) suggests a low likelihood of exploitation at this time. However, because an attacker requires authenticated access to the backup configuration, the risk remains for organizations in environments where backup management users are widely distributed. The vulnerability is not currently listed in CISA’s KEV catalog.
OpenCVE Enrichment