CVE-2026-105324: critical vulnerability in ASUSTOR Inc. ADM
An HTTP header injection vulnerability was found in the ADM
Published
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.2epss 0.7%
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
nono source reports it
An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter, the attacker can leverage the underlying web server's X-Sendfile mechanism to retrieve sensitive files without authentication.
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RWC1 as well as from ADM 5.0.0 through ADM 5.1.4.RL21.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Affected products
ASUSTOR Inc. · ADMRelated CVEs — ASUSTOR Inc. ADM
In the same product, most dangerous first.
CVE-2026-6644CRITICALA command injection vulnerability was found in the PPTP VPN Clients on the ADMEPSS 2.1%CVE-2026-6643HIGHA stack-based buffer overflow vulnerability in the VPN Clients on the ADMEPSS 0.8%CVE-2026-67244HIGHA format string vulnerability was found in the Notification OAuth settings of ADMEPSS 0.5%CVE-2026-67248HIGHA stack-based buffer overflow vulnerability was found in the File Explorer on the ADMEPSS 0.5%CVE-2026-18188HIGHA format string vulnerability was found in the Rsync Backup on the ADMEPSS 0.5%CVE-2026-18187HIGHA format string vulnerability was found in the Internal Backup on the ADMEPSS 0.5%