CVE-2026-105324: fallo crítico en ASUSTOR Inc. ADM
An HTTP header injection vulnerability was found in the ADM
Publicada el
28Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 9.2epss 0.7%
probabilidad de explotación
0.7%top 50% de las CVE
explotación observada
noninguna fuente lo reporta
An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter, the attacker can leverage the underlying web server's X-Sendfile mechanism to retrieve sensitive files without authentication.
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RWC1 as well as from ADM 5.0.0 through ADM 5.1.4.RL21.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Productos afectados
ASUSTOR Inc. · ADMCVEs relacionadas — ASUSTOR Inc. ADM
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-6644CRITICALA command injection vulnerability was found in the PPTP VPN Clients on the ADMEPSS 2.1%CVE-2026-6643HIGHA stack-based buffer overflow vulnerability in the VPN Clients on the ADMEPSS 0.8%CVE-2026-67244HIGHA format string vulnerability was found in the Notification OAuth settings of ADMEPSS 0.5%CVE-2026-67248HIGHA stack-based buffer overflow vulnerability was found in the File Explorer on the ADMEPSS 0.5%CVE-2026-18188HIGHA format string vulnerability was found in the Rsync Backup on the ADMEPSS 0.5%CVE-2026-18187HIGHA format string vulnerability was found in the Internal Backup on the ADMEPSS 0.5%