CVE-2026-105324: falha crítica em ASUSTOR Inc. ADM
An HTTP header injection vulnerability was found in the ADM
Publicada em
28Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 9.2epss 0.7%
probabilidade de exploração
0.7%top 50% das CVEs
exploração observada
nãonenhuma fonte reporta
An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter, the attacker can leverage the underlying web server's X-Sendfile mechanism to retrieve sensitive files without authentication.
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RWC1 as well as from ADM 5.0.0 through ADM 5.1.4.RL21.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Produtos afetados
ASUSTOR Inc. · ADMCVEs relacionadas — ASUSTOR Inc. ADM
No mesmo produto, das mais perigosas para as menos.
CVE-2026-6644CRITICALA command injection vulnerability was found in the PPTP VPN Clients on the ADMEPSS 2.1%CVE-2026-6643HIGHA stack-based buffer overflow vulnerability in the VPN Clients on the ADMEPSS 0.8%CVE-2026-67244HIGHA format string vulnerability was found in the Notification OAuth settings of ADMEPSS 0.5%CVE-2026-67248HIGHA stack-based buffer overflow vulnerability was found in the File Explorer on the ADMEPSS 0.5%CVE-2026-18188HIGHA format string vulnerability was found in the Rsync Backup on the ADMEPSS 0.5%CVE-2026-18187HIGHA format string vulnerability was found in the Internal Backup on the ADMEPSS 0.5%