PT-2026-5771 · Asustor · Asustor Adm
CVE-2026-24936
·
Publicado
2026-02-03
·
Atualizado
2026-03-12
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ASUSTOR ADM versions 4.1.0 through 4.3.3.ROF1
ASUSTOR ADM versions 5.0.0 through 5.1.1.RCI1
Description
An improper input parameters validation issue exists in a specific CGI program when a particular function is enabled during Active Directory (AD) domain joining. This allows an unauthenticated remote attacker to write arbitrary data to any file on the system. Successful exploitation can lead to overwriting critical system files and complete system compromise.
Recommendations
For ASUSTOR ADM versions 4.1.0 through 4.3.3.ROF1, disable the specific function used during AD domain joining.
For ASUSTOR ADM versions 5.0.0 through 5.1.1.RCI1, disable the specific function used during AD domain joining.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Asustor Adm