Format String Vulnerability in Asustor ADM Internal Backup
CVE-2026-18187
7.1HIGH
What is CVE-2026-18187?
A format string vulnerability exists within the Internal Backup feature of Asustor's ADM. This issue arises when user-controlled input is improperly handled in an error response, which can lead to the exploitation of unsafe format string operations. An authenticated attacker can leverage this vulnerability to potentially disclose sensitive memory information or trigger denial of service conditions for the affected CGI process.
Affected Version(s)
ADM Linux 5.0.0 <= 5.1.3.RI81
ADM Linux 4.1.0 <= 4.3.3.RUN1
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications
