logo

CVE-2026-24936: Critical ASUSTOR Flaw (CVSS 9.5) Allows Remote System Takeover

ID: 1632306e-dcc4-56c1-adbc-edc21534f119

STIX ID: report--1632306e-dcc4-56c1-adbc-edc21534f119

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-02-04

Date Updated: 2026-04-23

Author: Ddos

...
...

ASUSTOR disclosed CVE-2026-24936, a critical (CVSS 9.5) arbitrary file-write vulnerability in a CGI endpoint used for Active Directory joining in ASUSTOR ADM that allows unauthenticated remote attackers to overwrite system files and potentially achieve full OS compromise; affected versions span ADM 4.1.0–4.3.3.ROF1 and 5.0.0–5.1.1.RCI1. ASUSTOR has released a patch (upgrade to ADM 5.1.2.RE31 or later) and advises immediate updates or mitigations (disable AD join or restrict management access) due to the high risk to NAS devices and backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.