{"id":404864,"date":"2026-08-22T04:47:44","date_gmt":"2026-08-22T04:47:44","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=404864"},"modified":"2026-08-22T04:47:44","modified_gmt":"2026-08-22T04:47:44","slug":"asustor-adm-4-3-3-rwc1","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/asustor-adm-4-3-3-rwc1\/","title":{"rendered":"The home ASUSTOR still needs ADM 4.3.3.RWC1"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The ASUSTOR under the desk is the house. AS-2026-019 says ADM will let a signed-in user walk a path out of the VPN certificate folder, the wallpaper folder, and the IHM log path. That is your photo library, the shop share, and the backup jobs that land on this box. Updating a PC does not close it. Sign into ADM, open Update, and take 4.3.3.RWC1 on the 4 train or 5.1.4.RJV2 on the 5 train.<\/p><div id=\"mwtad3996340239\" class=\"gas_fallback-ad_309684--placement_400588\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-asustor-overview.png\" alt=\"ASUSTOR NAS on a shelf next to a monitor showing ADM Update at 4.3.3.RWC1\" class=\"wp-image-404862\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-asustor-overview.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-asustor-overview-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-asustor-overview-1024x683.png 1024w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><figcaption class=\"wp-element-caption\">The NAS is the hole.<\/figcaption><\/figure>\n\n\n\n<div id=\"mwtad122686814\" class=\"gas_fallback-ad_309747-ad_309691-placement_400589\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Overview<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What broke<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">ASUSTOR published <a href=\"https:\/\/www.asustor.com\/security\/security_advisory_detail?id=68\" target=\"_blank\" rel=\"noopener\">AS-2026-019<\/a> for ADM. Revision 4 is dated 17 August 2026. The statement is blunt: a path traversal vulnerability was found in the VPN Clients, Wallpaper component and IHM on ADM. Affected builds run from ADM 4.1.0 through ADM 4.3.3.RUN1, and from ADM 5.0.0 through ADM 5.1.3.RI81. The close is ADM 5.1.4.RJV2 and ADM 4.3.3.RWC1.<\/p>\n\n\n\n<div id=\"mwtad3267824647\" class=\"mwtadp1 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"> \r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"7312657698\"><\/ins>\r\n <\/div><p class=\"wp-block-paragraph\">Three CVEs sit under that advisory. <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-67245\" target=\"_blank\" rel=\"noopener\">CVE-2026-67245<\/a> is High, CVSS4 7.0. User-controlled certificate name input is not checked hard enough before ADM builds the VPN upload path. An authenticated attacker with high privileges can write a certificate file outside the intended VPN directory. <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-67246\" target=\"_blank\" rel=\"noopener\">CVE-2026-67246<\/a> is Medium, CVSS4 6.9. Wallpaper path input is not checked hard enough either. An authenticated high-privilege user can reach or change files outside the wallpaper folder. <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-67247\" target=\"_blank\" rel=\"noopener\">CVE-2026-67247<\/a> is High, CVSS4 7.1. Disk serial input used to build an IHM log database path is not validated. That one is PR:L, so a low-privilege signed-in account is enough. The first two need high privileges. Credit on the advisory goes to Jincheng Wang of Nanjing University of Posts and Telecommunications.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Path traversal, in English, is a crafted string that walks out of the folder ADM meant to use. Dot-dot style names, or a serial that points somewhere else, can make the box open or write a file you never asked for. The attacker still needs a live ADM login. They do not need you to click a random page on the public internet. A reused admin password, a shared shop account, or a leftover low-privilege user on 67247 is the cast.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ASUSTOR has not said these CVEs are being used in the wild. CISA has not listed 67245, 67246, or 67247 on the <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noopener\">Known Exploited Vulnerabilities catalog<\/a>. The ADM builds are posted. That is the cheap window.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Who is in range<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Anyone running ADM 4.1.0 through 4.3.3.RUN1, or ADM 5.0.0 through 5.1.3.RI81, on an ASUSTOR NAS. The home box under the TV and the shop file server with the same ADM train are the same product. A guest share does not put you out of range if someone can still reach the ADM desktop.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If Settings already shows 4.3.3.RWC1 on a 4.x box, or 5.1.4.RJV2 or newer on a 5.x box, confirm Current Version after the reboot anyway. &#8220;I turned auto-update on last year&#8221; is not a build string. Write down the number before and after Check for Updates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Synology, QNAP, TrueNAS, a bare USB drive, or a Windows share are not this brief. Do not flash ASUSTOR ADM onto another brand. A house that only has a router is a different click.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What the vendor shipped<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>ADM 5.0 and 5.1: upgrade to ADM 5.1.4.RJV2 or above. ASUSTOR released that build on 3 August 2026.<\/li>\n<li>ADM 4.3, 4.2, and 4.1: upgrade to ADM 4.3.3.RWC1 or above. ASUSTOR released that build on 17 August 2026.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Match your branch. A 4.x box takes 4.3.3.RWC1. A 5.x box takes 5.1.4.RJV2 or newer. Do not stop at 4.3.3.RUN1 or 5.1.3.RI81. Those are the last affected floors on each train.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The in-ADM path is Settings, then Update &amp; Restore or ADM Update, then Check for Updates. Install the matching floor. Leave the NAS powered. Confirm Current Version after the box comes back. ASUSTOR&#8217;s own Live Update is the installer. Do not grab a random &#8220;NAS update&#8221; zip from a search result.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What this is not<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Not an unauthenticated WAN remote-code story. Every CVE on AS-2026-019 needs an authenticated ADM session. Two of them need high privileges. 67247 is the low-privilege path traversal.<\/li>\n<li>Not closed by updating Windows, macOS, or the browser on the desk. The ADM build on the NAS is the close.<\/li>\n<li>Not every NAS brand. This brief is ASUSTOR ADM only.<\/li>\n<li>Not on CISA KEV. ASUSTOR has not claimed in-the-wild use.<\/li>\n<li>Not done if Check downloaded a build and you never let the NAS reboot into it. Trust Current Version, not the download progress bar alone.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-asustor-house.png\" alt=\"Do This Now card: Flash ADM 4.3.3.RWC1, in range You plus the shop, urgency This week, then Update\" class=\"wp-image-404863\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-asustor-house.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-asustor-house-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-asustor-house-1024x683.png 1024w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><figcaption class=\"wp-element-caption\">ADM should read 4.3.3.RWC1 (or 5.1.4.RJV2 on the 5 train).<\/figcaption><\/figure>\n\n\n\n<div id=\"mwtad1432096542\" class=\"gas_fallback-ad_309748-ad_309691-placement_400590\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Do This Now<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>In range:<\/strong> You, plus the shop. ASUSTOR ADM below 4.3.3.RWC1 on the 4 train, or below 5.1.4.RJV2 on the 5 train.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Urgency:<\/strong> This week. Authenticated path traversal across VPN Clients, Wallpaper, and IHM. The 4.x floor landed 17 August 2026.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>On a PC already on the same LAN as the NAS, open the ADM desktop in a browser. Sign in with an account that can run updates.<\/li>\n<li>Open Settings, then Update &amp; Restore or ADM Update. Click Check for Updates. Install 4.3.3.RWC1 on a 4.x box, or 5.1.4.RJV2 on a 5.x box. Leave the NAS powered while it applies the build.<\/li>\n<li>When ADM comes back, sign in and read Current Version again. You want 4.3.3.RWC1 or newer on 4.x, or 5.1.4.RJV2 or newer on 5.x.<\/li>\n<\/ol>\n\n\n\n<div id=\"mwtad3086162720\" class=\"gas_fallback-ad_309749-ad_309691-placement_400591\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5354318971\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Who can skip<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>You do not own an ASUSTOR NAS.<\/li>\n<li>Current Version already shows 4.3.3.RWC1 or newer on a 4.x box, or 5.1.4.RJV2 or newer on a 5.x box, and you confirmed it after the reboot.<\/li>\n<li>Synology, QNAP, TrueNAS, WD My Cloud, or a bare USB drive: different product, different brief.<\/li>\n<li>You already replaced the NAS this month and the new one is not an ASUSTOR on an affected ADM floor.<\/li>\n<\/ul>\n\n\n\n<div id=\"mwtad594621214\" class=\"gas_fallback-ad_309750-ad_309691-placement_400592\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4041237300\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Why it matters<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Own the NAS and you own the family photos, the shop invoices, the Time Machine or backup jobs, and every share the house treats as local disk. A path traversal that writes or opens the wrong file is how that pile stops being &#8220;just storage.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ASUSTOR&#8217;s attacker is already signed in. A reused admin password. A shop account shared on a sticky note. A leftover low-privilege user who can still hit IHM logs on 67247. The hole is not a stranger typing your WAN IP with no login. It is someone who already has a door into ADM, then walks past the folder ADM meant to keep them in.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The PC on the desk is not this box. Updating Chrome or Windows leaves ADM sitting on 4.3.3.RUN1 or 5.1.3.RI81. CISA has not added these CVEs to KEV. ASUSTOR did not claim a victim count and did not say the bugs are in the wild. Waiting is still how an authenticated path traversal sits on the machine every laptop in the house mounts.<\/p>\n\n\n\n<div id=\"mwtad4157813198\" class=\"gas_fallback-ad_309751-ad_309691-placement_400593\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3690286463\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">The bottom line<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">On a PC already on the LAN<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Use a laptop or desktop on the same network as the ASUSTOR. Do not try this from a phone on cellular. ADM lives on the LAN, or on the remote path you already set up and trust.<\/li>\n<li>In the browser, open the ADM address you normally use. That is often the NAS hostname or the LAN IP on the sticker. Turn off a random public VPN on that laptop first if it blocks local reaches.<\/li>\n<li>Sign in. You need an account that can open Settings and run ADM Update. If you only have a read-only share user, escalate to the admin account you set at first boot.<\/li>\n<li>Open Settings. In the left list find Update &amp; Restore or ADM Update. Some builds label it ADM Update only. Click it. Read Current Version and write the string down.<\/li>\n<li>Click Check for Updates. If ADM offers 4.3.3.RWC1 on a 4.x train, or 5.1.4.RJV2 on a 5.x train, install it. Leave the NAS powered. A mid-update unplug is how you get a brick.<\/li>\n<li>When the box comes back, sign in again and open the same Update page. Current Version must show the new floor. Trust that line, not a toast that flashed during the download.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">What you should see<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">On ADM Update, under Current Version, the string should read 4.3.3.RWC1 on a 4.x box, or 5.1.4.RJV2 or newer on a 5.x box. Some screens also say you are on the latest version after Check. Clients may drop for a minute while services restart. That is expected. Shares come back when ADM finishes. Trust the version string.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">If Check never moves<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Try another browser on the same LAN. Confirm you are signed in as an admin-capable user. A shop firewall that blocks the NAS from reaching ASUSTOR will sit on Check with nothing to install. Use the network the NAS already uses for Live Update.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Manual install is the fallback when Live Update cannot reach ASUSTOR. Download the ADM build ASUSTOR signed for your exact train from ASUSTOR&#8217;s own support pages, then use the manual update path in ADM Update. Do not grab a file from a random &#8220;NAS firmware&#8221; site. Do not flash a 5.x package onto a 4.x box, or the reverse. Leave the unit powered for the whole apply.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If Check returns nothing and Current Version is still 4.3.3.RUN1 or 5.1.3.RI81, confirm you are on ADM and not looking at an App Central package version. App updates are not the ADM floor.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The other box in the house<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Every ASUSTOR on the LAN needs its own Current Version check. One leftover DR unit on 5.1.3.RI81 is still in range.<\/li>\n<li>The shop front-desk NAS and the home media box are separate sign-ins. Updating one does not patch the other.<\/li>\n<li>Synology or QNAP in the same building is a different admin and a different brief. Closing those boxes does not close ASUSTOR ADM.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">When you are done<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Current Version shows 4.3.3.RWC1 or newer on every 4.x ASUSTOR, or 5.1.4.RJV2 or newer on every 5.x ASUSTOR. Shares remount. The other ASUSTOR in the house got the same pass. You needed a new ADM floor. You have it.<\/p>\n\n<div id=\"mwtad412756718\" class=\"gas_fallback-ad_176819-ad_309691-placement_400595\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The ASUSTOR under the desk is the house. AS-2026-019 says ADM will let a signed-in user walk a path out of the VPN certificate folder, the wallpaper folder, and the IHM log path. That is &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"The home ASUSTOR still needs ADM 4.3.3.RWC1\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/asustor-adm-4-3-3-rwc1\/#more-404864\" aria-label=\"Read more about The home ASUSTOR still needs ADM 4.3.3.RWC1\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":404862,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3605],"tags":[],"class_list":["post-404864","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/404864","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=404864"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/404864\/revisions"}],"predecessor-version":[{"id":404884,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/404864\/revisions\/404884"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/404862"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=404864"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=404864"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=404864"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}