logo

PoC Disclosed for Critical Root ASUSTOR ADM RCE Flaw

ID: 88b4559f-1655-53cb-ae00-d66531f339e7

STIX ID: report--88b4559f-1655-53cb-ae00-d66531f339e7

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Divya

...
...

ASUSTOR ADM contains a critical OS command injection in the PPTP VPN client (CVE-2026-6644, CVSS v4.0 9.4) where an unsanitized PPTP server address is written into pppd's pty directive, enabling an authenticated admin to execute arbitrary root commands; a Python PoC is public and ASUSTOR released ADM 5.1.3.RGO1 to remediate—administrators should update firmware, change default credentials, and restrict management access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.