PT-2026-33723 · Adm · Adm
Published
2026-04-20
·
Updated
2026-05-20
·
CVE-2026-6644
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
ADM versions 4.1.0 through 4.3.3.RR42
ADM versions 5.0.0 through 5.1.2.REO1
Description
A command injection issue exists in the PPTP VPN Clients of ASUSTOR ADM. This occurs because user-supplied input is not sufficiently validated before being passed to a system shell, allowing an authenticated administrative user to break out of the restricted web environment and execute arbitrary root-level code on the underlying operating system. Successful exploitation can lead to Remote Code Execution (RCE) and full system compromise. Approximately 14,537 ASUSTOR-related exposed assets have been identified.
Recommendations
Update ADM versions 4.1.0 through 4.3.3.RR42 to a patched version.
Update ADM versions 5.0.0 through 5.1.2.REO1 to version 5.1.3.RGO1 or 5.1.3.RGL1.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adm