Description
A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-controlled input is not properly validated before being decoded and copied into a fixed-size stack buffer. An authenticated attacker can exploit this issue to cause denial of service of the affected CGI process. Further impact may be possible depending on exploitability and runtime protections.
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
Published: 2026-07-30
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack-based buffer overflow exists in the File Explorer component of ASUSTOR Devicemanagement (ADM). User-controlled data is copied into a fixed-size stack buffer without proper validation, allowing an authenticated attacker to trigger an overflow. Exploitation leads to a denial of service of the affected CGI process, as the overflow corrupts the stack and crashes the process. The description notes that further impact may be possible if runtime protections are bypassed, but the primary consequence disclosed is a DoS.

Affected Systems

Affected are ASUSTOR Inc. ADM systems. Vulnerable versions are ADM 4.1.0 through 4.3.3.RUN1 and ADM 5.0.0 through 5.1.3.RI81. No other vendors or product line is listed.

Risk and Exploitability

The CVSS score of 8.7 classifies this as a high severity vulnerability. The EPSS score is below 1%, indicating a low likelihood of exploitation in the wild at this time. It is not listed in CISA’s KEV catalog. Exploitation requires authentication and local network or system access, as the attacker must supply malicious input to the vulnerable File Explorer CGI. If resolved, the attack would simply crash the CGI process; if not, an attacker could potentially chain exploitation to achieve additional privilege or system takeover depending on runtime defenses.

Generated by OpenCVE AI on August 3, 2026 at 11:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ADM to a version released after 4.3.3.RUN1 or 5.1.3.RI81 to contain the fixed stack validation code.
  • If upgrade is not immediately possible, restrict or disable the File Explorer CGI endpoint so that authenticated users cannot invoke it, thereby preventing the buffer overflow.
  • Apply network or host‑based filtering to limit regions or IPs able to reach the vulnerable CGI, and monitor for abnormal request patterns that could indicate attempts to supply oversized input.

Generated by OpenCVE AI on August 3, 2026 at 11:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Asustor
Asustor adm
Vendors & Products Asustor
Asustor adm

Thu, 30 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-controlled input is not properly validated before being decoded and copied into a fixed-size stack buffer. An authenticated attacker can exploit this issue to cause denial of service of the affected CGI process. Further impact may be possible depending on exploitability and runtime protections. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
Title A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ASUSTOR1

Published:

Updated: 2026-08-04T07:32:46.227Z

Reserved: 2026-07-29T01:38:34.119Z

Link: CVE-2026-67248

cve-icon Vulnrichment

Updated: 2026-07-30T13:24:21.564Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T05:16:39.157

Modified: 2026-08-04T14:05:45.857

Link: CVE-2026-67248

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:30:03Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow