What is CVE-2026-67245?
CVE-2026-67245 is a path traversal vulnerability in the VPN Clients on ADM devices. Insufficient validation of user-controlled certificate name input allows the construction of an arbitrary upload destination path. Authenticated attackers can exploit this to write files to unintended locations, and it is recommended to disable the affected VPN client functionality until a patch is applied.
Azərbaycanca: CVE-2026-67245 ADM cihazlarındakı VPN müştərilərində tapılmış path traversal zəifliyidir. İstifadəçi tərəfindən idarə olunan sertifikat adı daxiletməsi kifayət qədər yoxlanılmadığı üçün autentifikasiya olunmuş hücumçu fayl yükləmə yolunu manipulyasiya edə bilər. Təsirə məruz qalan sistemlərdə VPN müştəri funksiyasını müvəqqəti olaraq deaktiv etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which functionality on ADM devices does CVE-2026-67245 affect?
The vulnerability was found in the VPN Clients on ADM devices.
What can an attacker achieve by exploiting CVE-2026-67245?
An authenticated attacker can manipulate the file upload path to write files to unintended locations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.