Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-18186— A stored format string vulnerability was found in the FTP Backup on the ADM

CVSS 7.1 · High EPSS 0.23% · P13

Possible ATT&CK Techniques 1AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 2

VendorProductVersion RangeStatus
ASUSTOR Inc.ADM5.0.0≤ 5.1.3.RI81affected
4.1.0≤ 4.3.3.RUN1affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-18186

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
A stored format string vulnerability was found in the FTP Backup on the ADM
Source: CVE Program / CVE List V5
Vulnerability Description
A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration data may be written into a task log and later processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected CGI process. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用外部控制的格式字符串
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
ASUSTOR Inc.ADM 5.0.0 ~ 5.1.3.RI81 -

II. Public POCs for CVE-2026-18186

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18186

登录查看更多情报信息。

Vendor Advisories for CVE-2026-18186 (1)

Same Patch Batch · ASUSTOR Inc. · 2026-07-30 · 8 CVEs total

CVE-2026-672488.7 HIGHA stack-based buffer overflow vulnerability was found in the File Explorer on the ADM
CVE-2026-672448.6 HIGHA format string vulnerability was found in the Notification OAuth settings of ADM
CVE-2026-181887.1 HIGHA format string vulnerability was found in the Rsync Backup on the ADM
CVE-2026-181877.1 HIGHA format string vulnerability was found in the Internal Backup on the ADM
CVE-2026-672477.1 HIGHA path traversal vulnerability was found in the IHM Log handling of ADM
CVE-2026-672457.0 HIGHA path traversal vulnerability was found in the VPN Clients on the ADM
CVE-2026-672466.9 MEDIUMA path traversal vulnerability was found in the Wallpaper component of ADM

IV. Related Vulnerabilities

V. Comments for CVE-2026-18186

No comments yet


Leave a comment