Chúng tôi sử dụng cookie để giúp cải thiện trang web của mình. Vui lòng Đọc dữ liệu của chúng tôi Chính sách cookie .

AS-2026-018: ADM

2026-07-29

Severity

Important

Status

Ongoing


Statement

A stored format string vulnerability was found in FTP Backup, Internal Backup, Rsync Backup and Notification settings on the ADM.

Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.


Affected Products

Product Severity Fixed Release Availability
ADM 5.0 and 5.1 Important Ongoing
ADM 4.3, 4.2 and 4.1 Important Ongoing

Detail

  • CVE-2026-18186
    • Severity: High
    • CVSS4 Base Score: 7.1
    • CVSS4 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
    • A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration data may be written into a task log and later processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected CGI process. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
  • CVE-2026-18187
    • Severity: High
    • CVSS4 Base Score: 7.1
    • CVSS4 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
    • A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be included in an error response and processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected CGI process. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
  • CVE-2026-18188
    • Severity: High
    • CVSS4 Base Score: 7.1
    • CVSS4 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
    • A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsync backup configuration or log data may be processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected backup component. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
  • CVE-2026-67244
    • Severity: High
    • CVSS4 Base Score: 8.6
    • CVSS4 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
    • A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-controlled notification configuration input may be processed through an unsafe format string operation. An authenticated administrator can exploit this issue to disclose memory information or cause denial of service of the affected component. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.

Reference

Acknowledgement

Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications


Revision

Revision Date Description
1 2026-07-29 Initial public release.
2 2026-07-30 CVE ID (CVE-2026-18186, CVE-2026-18187, CVE-2026-18188, CVE-2026-67244) are assigned for the issues.