← Vulnerability feed

Vulnerability record · CVE-2026-18186 · published 30 July 2026

CVE-2026-18186: Asustor data master vulnerability

AAsustor · Data Master

A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration data may be written into a task log and later processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected CGI process. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.

7.1 CVSS 4.0 High EPSS 0.46% · top 62.3% CWE-134 · CWE-134
7.1CVSS 4.0 base score
0.46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
4 Aug 2026Last modified by NVD

Description

A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration data may be written into a task log and later processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected CGI process. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-18186 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-12313Asustor data master os command injection vulnerabilityOS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity…EPSS 4.4%9.5CVE-2026-24936Asustor data master improper input validation vulnerabilityWhen a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI progr…EPSS 0.81%9.4CVE-2026-6644Asustor data master os command injection vulnerabilityA command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the r…EPSS 2.1%9.2CVE-2026-3179Asustor data master path traversal vulnerabilityThe FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MI…EPSS 0.77%8.9CVE-2026-24932Asustor data master improper certificate validation vulnerabilityThe DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Although the connection uses HTTPS,…EPSS 0.21%8.9CVE-2026-24933Asustor data master improper certificate validation vulnerabilityThe API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validat…EPSS 0.21%8.8CVE-2023-2910Asustor data master command injection vulnerabilityImproper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Ma…EPSS 1.6%8.8CVE-2023-3697Asustor data master path traversal vulnerabilityPrinter service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and …EPSS 0.66%

Source: NIST National Vulnerability Database (record CVE-2026-18186), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.