CVE-2026-67248

HIGH

Asustor Inc. Adm < 5.1.3.RI81 - Buffer Overflow

Title source: rule
STIX 2.1

Description

A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-controlled input is not properly validated before being decoded and copied into a fixed-size stack buffer. An authenticated attacker can exploit this issue to cause denial of service of the affected CGI process. Further impact may be possible depending on exploitability and runtime protections. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.

References (1)

Core 1
Core References

Scores

CVSS v4 8.7
EPSS 0.0023
EPSS Percentile 13.9%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-121
Status published
Products (2)
ASUSTOR Inc./ADM 4.1.0 - 4.3.3.RUN1
ASUSTOR Inc./ADM 5.0.0 - 5.1.3.RI81
Published Jul 30, 2026
Tracked Since Jul 30, 2026