PT-2026-66360 · Asustor · Adm+1
CVE-2026-67247
·
Published
2026-07-30
·
Updated
2026-08-04
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ADM versions 4.1.0 through 4.3.3.RUN1
ADM versions 5.0.0 through 5.1.3.RI81
Description
A path traversal issue exists in the IHM Log handling. This occurs because the
disk serial input provided by a user is not sufficiently validated before being used to construct the path of an IHM log database file. An authenticated attacker can exploit this to access unintended filesystem paths or log database files. Path traversal is a flaw that allows an attacker to access files and directories that are stored outside the web root folder.Recommendations
Update ADM versions 4.1.0 through 4.3.3.RUN1 to a newer version.
Update ADM versions 5.0.0 through 5.1.3.RI81 to a newer version.
Restrict the use of the
disk serial input until a patch is applied.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adm
Data Master