An improper Input Validation vulnerability allows injecting arbitrary values of the NAS configuration file in ASUSTOR ADM. This could potentially lead to system misconfiguration and break the format of the configuation file, causing the NAS to exhibit unexpected behavior.
This issue affects ADM: from 4.1 before 4.3.1.R5A1.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Wed, 09 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 09 Jul 2025 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Input Validation vulnerability allows injecting arbitrary values of the NAS configuration file in ASUSTOR ADM . This could potentially lead to system misconfiguration and break the format of the configuation file, causing the NAS to exhibit unexpected behavior. This issue affects ADM: from 4.1 before 4.3.1.R5A1. | An improper Input Validation vulnerability allows injecting arbitrary values of the NAS configuration file in ASUSTOR ADM. This could potentially lead to system misconfiguration and break the format of the configuation file, causing the NAS to exhibit unexpected behavior. This issue affects ADM: from 4.1 before 4.3.1.R5A1. |
Wed, 09 Jul 2025 07:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Input Validation vulnerability allows injecting arbitrary values of the NAS configuration file in ASUSTOR ADM . This could potentially lead to system misconfiguration and break the format of the configuation file, causing the NAS to exhibit unexpected behavior. This issue affects ADM: from 4.1 before 4.3.1.R5A1. | |
Title | An improper input validation vulnerability was found on manipulating configuration of ADM | |
Weaknesses | CWE-20 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: ASUSTOR1
Published: 2025-07-09T07:06:08.150Z
Updated: 2025-07-09T13:54:52.248Z
Reserved: 2025-07-09T06:11:51.237Z
Link: CVE-2025-7378

Updated: 2025-07-09T13:54:46.082Z

Status : Awaiting Analysis
Published: 2025-07-09T07:15:24.667
Modified: 2025-07-10T13:17:30.017
Link: CVE-2025-7378

No data.