PT-2026-33722 · Adm · Adm

Yu-Xiang Huang

·

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-6643

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ADM versions 4.1.0 through 4.3.3.RR42 ADM versions 5.0.0 through 5.1.2.REO1
Description A stack-based buffer overflow exists in the VPN Clients. The issue is caused by the use of unbounded sscanf() and the direct passing of user-controlled data to printf(). Because Position Independent Executable (PIE) and Stack Canary protections are absent, an authenticated remote attacker can execute arbitrary code as the web server user.
Recommendations Update versions 4.1.0 through 4.3.3.RR42 to a version containing the fix. Update versions 5.0.0 through 5.1.2.REO1 to a version containing the fix.

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6643

Affected Products

Adm