Critical ASUSTOR NAS Security Flaw Enables Complete Device Takeover
ID: ab00fcb2-873c-5de6-b9a1-89774450683a
STIX ID: report--ab00fcb2-873c-5de6-b9a1-89774450683a
Feed Name: GBHackers
A critical improper input validation vulnerability (CVE-2026-24936) in ASUSTOR Data Master (ADM) allows unauthenticated remote attackers to perform arbitrary file writes while the device attempts to join an Active Directory domain, potentially leading to full system compromise and root access; CVSS v4.0 base score 9.5. ASUSTOR released a patch for ADM 5.1.2.RE31 (users of 5.0.0–5.1.1.RCI1 must upgrade) while ADM 4.x versions remain unpatched and should be isolated or have AD-joining disabled until a fix is issued.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
