CVE-2025-7378: An improper input validation vulnerability was found on manipulating configuration of ADM
An improper Input Validation vulnerability allows injecting arbitrary values of the NAS configuration file in ASUSTOR ADM. This could potentially lead to system misconfiguration and break the format of the configuation file, causing the NAS to exhibit unexpected behavior. This issue affects ADM: from 4.1 before 4.3.1.R5A1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ASUSTOR ADMto a version that resolves this vulnerability.Fixed in 4.3.1.R5A1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7378?
CVE-2025-7378 is classified as an Improper Input Validation vulnerability.
How do I fix CVE-2025-7378?
To fix CVE-2025-7378, update your ASUSTOR ADM software to version 4.3.1.R5A1 or later.
What can happen if CVE-2025-7378 is exploited?
Exploitation of CVE-2025-7378 can lead to system misconfiguration and unexpected behavior of the NAS device.
Which versions of ASUSTOR ADM are affected by CVE-2025-7378?
CVE-2025-7378 affects ASUSTOR ADM versions between 4.1 and 4.3.1.R5A1.
Is there a workaround for CVE-2025-7378?
As of now, there are no documented workarounds for CVE-2025-7378; the recommended action is to apply the software update.