Description
A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled disk serial input is not sufficiently validated before being used to construct the path of an IHM log database file. An authenticated attacker can exploit this issue to cause the affected component to access an unintended filesystem path or log database file.
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
Published: 2026-07-30
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path traversal flaw exists in the IHM Log handling component of ASUSTOR’s ADM when it does not properly validate user‑controlled disk serial input before constructing the log database path. An attacker who can authenticate to the ADM interface can exploit this to read arbitrary files on the device’s filesystem, leading to information disclosure. The weakness is a classic directory traversal (CWE‑22).

Affected Systems

ASUSTOR Inc. ADM versions from 4.1.0 through 4.3.3.RUN1 and from 5.0.0 through 5.1.3.RI81 are affected. All installations of these releases are vulnerable until patched or upgraded beyond the listed versions.

Risk and Exploitability

The CVSS score of 7.1 rates it as a high‑severity vulnerability. However, the EPSS score of less than 1% indicates a very low probability of exploitation at the time of analysis, and it is not listed in the CISA KEV catalog. The attack is likely to occur through an authenticated web interface or API; a local or network attacker who can log in to ADM can trigger the path traversal. The risk lies mainly in the potential for confidential data exposure.

Generated by OpenCVE AI on August 4, 2026 at 11:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update ADM to the latest release that addresses the path traversal flaw as published by ASUSTOR; see the official security advisory for patch download and installation steps.
  • If an immediate update is not possible, restrict or disable access to the affected IHM Log handling endpoint for unauthenticated or untrusted users, and enforce strict firewall rules to limit connections.
  • After applying the patch or the access restriction, verify that the disk serial input handling no longer accepts anomalous characters by testing the log path construction functionality.

Generated by OpenCVE AI on August 4, 2026 at 11:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Asustor
Asustor adm
Vendors & Products Asustor
Asustor adm

Thu, 30 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled disk serial input is not sufficiently validated before being used to construct the path of an IHM log database file. An authenticated attacker can exploit this issue to cause the affected component to access an unintended filesystem path or log database file. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
Title A path traversal vulnerability was found in the IHM Log handling of ADM
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ASUSTOR1

Published:

Updated: 2026-08-04T07:32:11.961Z

Reserved: 2026-07-29T01:38:34.119Z

Link: CVE-2026-67247

cve-icon Vulnrichment

Updated: 2026-07-30T13:30:28.162Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T05:16:39.017

Modified: 2026-08-04T14:06:15.050

Link: CVE-2026-67247

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T12:00:10Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')