logo

ASUSTOR Issues Critical Patch: Command Injection Vulnerability Threatens ADM Users

ID: 6191e0b4-24e3-5e60-8bc5-48ad5dfabc17

STIX ID: report--6191e0b4-24e3-5e60-8bc5-48ad5dfabc17

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-21

Date Updated: 2026-04-23

Author: Ddos

...
...

ASUSTOR has issued an urgent advisory for CVE-2026-6644, a command injection vulnerability in the PPTP VPN Client of ASUSTOR Data Master (ADM) with a CVSS score of 9.4 that can allow remote code execution and full system compromise across multiple ADM versions; users on ADM 5.0 are advised to upgrade to ADM 5.1.3.RGL1 immediately while fixes for older branches are ongoing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.