CVE-2026-24936 Details
Description
When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI program allowing an unauthenticated remote attacker to write arbitrary data to any file on the system. By exploiting this vulnerability, attackers can overwrite critical system files, leading to a complete system compromise. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.1.RCI1.
A vulnerability exists in Asustor's ADM operating system, specifically in versions 4.1.0 through 4.3.3.ROF1 and 5.0.0 through 5.1.1.RCI1. When joining an Active Directory domain, a certain function can be enabled that introduces improper input validation in a CGI program. This flaw allows an unauthenticated remote attacker to write arbitrary data to any file on the system. Exploitation of this vulnerability could lead to overwriting critical system files, resulting in a complete system compromise.
Users can upgrade to Asustor ADM 5.1.2.RE31 or above. For ADM 4.3, 4.2, and 4.1 users, the fix is ongoing.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.asustor.com/security/security_advisory_detail?id=51 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| asustor data master | >= 4.1.0.rhu2, <= 4.3.3.rof1 >= 5.0.0.ra82, < 5.1.2.re51 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 19, 2026 | Initial Analysis | [email protected] |
| Feb 3, 2026 | New CVE Received | [email protected] |