logo

Critical ASUSTOR NAS Security Flaw Enables Complete Device Takeover

ID: ab00fcb2-873c-5de6-b9a1-89774450683a

STIX ID: report--ab00fcb2-873c-5de6-b9a1-89774450683a

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-02-04

Date Updated: 2026-04-22

Author: Divya

...
...

A critical improper input validation vulnerability (CVE-2026-24936) in ASUSTOR Data Master (ADM) allows unauthenticated remote attackers to perform arbitrary file writes while the device attempts to join an Active Directory domain, potentially leading to full system compromise and root access; CVSS v4.0 base score 9.5. ASUSTOR released a patch for ADM 5.1.2.RE31 (users of 5.0.0–5.1.1.RCI1 must upgrade) while ADM 4.x versions remain unpatched and should be isolated or have AD-joining disabled until a fix is issued.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.