logo

PoC Released for Critical ASUSTOR ADM Root RCE Vulnerability

ID: fe5e516c-8f67-5c82-bc42-a577d394f796

STIX ID: report--fe5e516c-8f67-5c82-bc42-a577d394f796

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Lucas Martin

...
...

A critical (CVSS v4.0 Base Score 9.4) OS command-injection vulnerability (CVE-2026-6644) in ASUSTOR ADM's PPTP VPN connection handler allows authenticated administrators to achieve root remote code execution by abusing an unsanitized PPTP server address written into pppd's pty directive; a public PoC has been published and an estimated ~19,000 ASUSTOR hosts are internet-facing. ASUSTOR issued a patch (ADM 5.1.3.RGO1) and the report urges immediate updates, removal of WAN exposure, changing default credentials, and disabling unused services such as PPTP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.