CVE-2026-18187 Details
Description
A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be included in an error response and processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected CGI process. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
A format string vulnerability has been identified in the Internal Backup feature of Asustor's ADM operating system. This vulnerability affects versions 4.1.0 through 4.3.3.RUN1, as well as versions 5.0.0 through 5.1.3.RI81. The issue arises because user-controlled task input can be included in error responses and processed through an unsafe format string operation. An authenticated attacker could exploit this vulnerability to disclose memory information or cause a denial-of-service condition in the affected CGI process.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.asustor.com/security/security_advisory_detail?id=67 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-134 | Use of Externally-Controlled Format String | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| asustor data master | >= 4.1.0.rhu2, <= 4.3.3.run1 >= 5.0.0.ra82, < 5.1.4.rjv2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 4, 2026 | Initial Analysis | [email protected] |
| Aug 4, 2026 | CVE Modified | [email protected] |
| Jul 30, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |