PT-2026-33723 · Adm · Adm

Published

2026-04-20

·

Updated

2026-05-20

·

CVE-2026-6644

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions ADM versions 4.1.0 through 4.3.3.RR42 ADM versions 5.0.0 through 5.1.2.REO1
Description A command injection issue exists in the PPTP VPN Clients of ASUSTOR ADM. This occurs because user-supplied input is not sufficiently validated before being passed to a system shell, allowing an authenticated administrative user to break out of the restricted web environment and execute arbitrary root-level code on the underlying operating system. Successful exploitation can lead to Remote Code Execution (RCE) and full system compromise. Approximately 14,537 ASUSTOR-related exposed assets have been identified.
Recommendations Update ADM versions 4.1.0 through 4.3.3.RR42 to a patched version. Update ADM versions 5.0.0 through 5.1.2.REO1 to version 5.1.3.RGO1 or 5.1.3.RGL1.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6644

Affected Products

Adm