What is CVE-2026-18186?
This is a stored format string vulnerability in the FTP Backup feature of ADM devices. An authenticated attacker can inject format specifiers via backup configuration data, which are later unsafely processed in a task log, potentially leading to information disclosure or arbitrary code execution. Immediate patching is recommended once the vendor update is available.
Azərbaycanca: Bu zəiflik ADM cihazlarında FTP Backup funksiyasında aşkarlanmış format string (format string) boşluğudur. Autentifikasiya olunmuş təcavüzkar, ehtiyat nüsxə konfiqurasiyasına xüsusi format spesifikatorları daxil edərək, log emalı zamanı potensial olaraq məlumat sızmasına və ya kod icrasına səbəb ola bilər. Təsirə məruz qalan sistemlərin dərhal istehsalçı tərəfindən təqdim edilən yeniləmə ilə patç edilməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Does exploiting CVE-2026-18186 require the attacker to be authenticated?
Yes, this is a stored format string vulnerability that can be exploited by an authenticated attacker.
In which functionality was CVE-2026-18186 discovered?
The vulnerability was discovered in the FTP Backup feature of ADM devices.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.