logo

Exploit Exposed: Public PoC Disclosed for Critical Root RCE in ASUSTOR ADM (CVE-2026-6644)

ID: 426c50a4-df2a-5226-933c-cf8fcdc646ed

STIX ID: report--426c50a4-df2a-5226-933c-cf8fcdc646ed

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Ddos

...
...

A critical authenticated remote root vulnerability (CVE-2026-6644) was disclosed in ASUSTOR ADM’s PPTP VPN Client: an unsanitized PPTP server address is written into pppd’s pty directive and executed via /bin/sh, allowing command injection and full system takeover. Proof-of-concept code is public, up to ~19,000 internet-facing ASUSTOR hosts may be reachable, and ASUSTOR published an emergency firmware update (ADM 5.1.3.RGO1) with guidance to restrict WAN management access and use strong admin credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.