CVE-2026-67248
Received Received - Intake

Stack-Based Buffer Overflow in ASUSTOR ADM File Explorer

Vulnerability report for CVE-2026-67248, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: ASUSTOR, Inc.

Description

A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-controlled input is not properly validated before being decoded and copied into a fixed-size stack buffer. An authenticated attacker can exploit this issue to cause denial of service of the affected CGI process. Further impact may be possible depending on exploitability and runtime protections. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-30
AI Q&A
2026-07-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
asustor adm From 4.1.0 (inc) to 4.3.3 (inc)
asustor adm From 5.0.0 (inc) to 5.1.3 (inc)
asustor adm From 4.1.0 (inc) to 4.3.3.RUN1 (inc)
asustor adm From 5.0.0 (inc) to 5.1.3.RI81 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stack-based buffer overflow vulnerability in the File Explorer component of ASUSTOR's ADM software. It occurs when user-controlled input is not properly validated before being decoded and copied into a fixed-size stack buffer. An authenticated attacker could exploit this to cause a denial of service in the affected CGI process.

Detection Guidance

Detecting this vulnerability requires checking the ADM version on your Asustor device. Compare your installed version against affected ranges: ADM 4.1.0 to 4.3.3.RUN1 or ADM 5.0.0 to 5.1.3.RI81. Use the ADM web interface or SSH to run 'cat /etc/version' to check the version.

Impact Analysis

An attacker could exploit this to crash the File Explorer CGI process, leading to service disruption. Further impact depends on runtime protections and exploitability, but denial of service is the primary risk.

Mitigation Strategies

Since no fixed releases are available, immediately restrict access to the File Explorer component. Disable unnecessary services, apply network-level restrictions, and monitor for unusual activity. Follow Asustor's security advisory updates for patches.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67248. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart