ASUSTOR Issues Critical Patch: Command Injection Vulnerability Threatens ADM Users
ID: 6191e0b4-24e3-5e60-8bc5-48ad5dfabc17
STIX ID: report--6191e0b4-24e3-5e60-8bc5-48ad5dfabc17
Feed Name: securityonline.info
Threat Score
ASUSTOR has issued an urgent advisory for CVE-2026-6644, a command injection vulnerability in the PPTP VPN Client of ASUSTOR Data Master (ADM) with a CVSS score of 9.4 that can allow remote code execution and full system compromise across multiple ADM versions; users on ADM 5.0 are advised to upgrade to ADM 5.1.3.RGL1 immediately while fixes for older branches are ongoing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
