Chúng tôi sử dụng cookie để giúp cải thiện trang web của mình. Vui lòng Đọc dữ liệu của chúng tôi Chính sách cookie .

AS-2026-019: ADM

2026-07-29

Severity

Important

Status

Ongoing


Statement

A path traversal vulnerability was found in the VPN Clients, Wallpaper component and IHM on the ADM.

Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.


Affected Products

Product Severity Fixed Release Availability
ADM 5.0 and 5.1 Important Ongoing
ADM 4.3, 4.2 and 4.1 Important Ongoing

Detail

  • CVE-2026-67245
    • Severity: High
    • CVSS4 Base Score: 7.0
    • CVSS4 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
    • A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is not sufficiently validated before being used to construct the upload destination path. An authenticated attacker can exploit this issue to write an uploaded certificate file outside the intended VPN certificate directory, subject to process privileges and filesystem permissions. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
  • CVE-2026-67246
    • Severity: Medium
    • CVSS4 Base Score: 6.9
    • CVSS4 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
    • A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is not sufficiently validated before being used for file access. An authenticated attacker can exploit this issue to access or manipulate files outside the intended wallpaper directory, subject to user permissions and filesystem restrictions. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
  • CVE-2026-67247
    • Severity: High
    • CVSS4 Base Score: 7.1
    • CVSS4 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
    • A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled disk serial input is not sufficiently validated before being used to construct the path of an IHM log database file. An authenticated attacker can exploit this issue to cause the affected component to access an unintended filesystem path or log database file. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.

Reference

Acknowledgement

Jincheng Wang (@winmt) from Nanjing University of Posts and Telecommunications


Revision

Revision Date Description
1 2026-07-29 Initial public release.
2 2026-07-30 CVE ID (CVE-2026-67245, CVE-2026-67246, CVE-2026-67247) are assigned for the issues.