PoC Disclosed for Critical Root ASUSTOR ADM RCE Flaw
ID: 88b4559f-1655-53cb-ae00-d66531f339e7
STIX ID: report--88b4559f-1655-53cb-ae00-d66531f339e7
Feed Name: GBHackers
Threat Score
ASUSTOR ADM contains a critical OS command injection in the PPTP VPN client (CVE-2026-6644, CVSS v4.0 9.4) where an unsanitized PPTP server address is written into pppd's pty directive, enabling an authenticated admin to execute arbitrary root commands; a Python PoC is public and ASUSTOR released ADM 5.1.3.RGO1 to remediate—administrators should update firmware, change default credentials, and restrict management access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
