PT-2026-5771 · Asustor · Asustor Adm

CVE-2026-24936

·

Publicado

2026-02-03

·

Atualizado

2026-03-12

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ASUSTOR ADM versions 4.1.0 through 4.3.3.ROF1 ASUSTOR ADM versions 5.0.0 through 5.1.1.RCI1
Description An improper input parameters validation issue exists in a specific CGI program when a particular function is enabled during Active Directory (AD) domain joining. This allows an unauthenticated remote attacker to write arbitrary data to any file on the system. Successful exploitation can lead to overwriting critical system files and complete system compromise.
Recommendations For ASUSTOR ADM versions 4.1.0 through 4.3.3.ROF1, disable the specific function used during AD domain joining. For ASUSTOR ADM versions 5.0.0 through 5.1.1.RCI1, disable the specific function used during AD domain joining.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24936

Produtos afetados

Asustor Adm