CVE-2026-6644 Details
Description
A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary code on the underlying operating system. This occurs due to insufficient validation of user-supplied input before it is passed to a system shell. Successful exploitation allows an attacker to achieve Remote Code Execution (RCE) and fully compromise the system. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RR42 as well as from ADM 5.0.0 through ADM 5.1.2.REO1.
A command injection vulnerability has been identified in the PPTP VPN clients on Asustor's ADM operating system. This vulnerability enables an administrative user to escape the confined web environment and execute arbitrary code on the underlying operating system. The issue arises from inadequate validation of user-supplied input before it is transmitted to a system shell. Successful exploitation of this vulnerability allows an attacker to achieve remote code execution and gain full control over the system. The vulnerability affects Asustor ADM versions 4.1.0 through 4.3.3.RR42, as well as 5.0.0 through 5.1.2.REO1.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://uky007.github.io/CVE-2026-6644/ | CISA-ADP | |
| https://https://www.asustor.com/security/security_advisory_detail?id=55 | [email protected] | Broken LinkVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| asustor data master | >= 4.1.0.rhu2, < 4.3.3.RR42 >= 5.0.0.ra82, < 5.1.2.reo1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 30, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | Initial Analysis | [email protected] |
| Apr 20, 2026 | New CVE Received | [email protected] |