Warning: Critical file‑overwrite in ASUSTOR ADM. Unauthenticated Attackers Can Compromise The NAS, Patch Immediately!
ID: a4058dc7-c480-5a3e-80a4-4a6f8359ac63
STIX ID: report--a4058dc7-c480-5a3e-80a4-4a6f8359ac63
Feed Name: CCB Advisories Feed
**ASUSTOR ADM arbitrary file write (CVE-2026-24936)** — A critical (CVSS 9.5) unauthenticated arbitrary file write vulnerability in ASUSTOR Data Master (ADM 4.1–5.0) can be triggered when joining an Active Directory domain, allowing attackers to overwrite system/configuration files, exfiltrate data, disrupt availability, or pivot within networks; ADM 5.1.2.RE31 mitigates the issue for ADM 5.0 while ADM 4.x versions currently lack a vendor patch and should be isolated or access-restricted until fixed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
