Vulnerability Details CVE-2026-24936
When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI program allowing an unauthenticated remote attacker to write arbitrary data to any file on the system. By exploiting this vulnerability, attackers can overwrite critical system files, leading to a complete system compromise.
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.1.RCI1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.3%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-24936
-
cpe:2.3:o:asustor:data_master:4.1.0.rhu2
-
cpe:2.3:o:asustor:data_master:4.1.0.rj72
-
cpe:2.3:o:asustor:data_master:4.1.0.rjd1
-
cpe:2.3:o:asustor:data_master:4.1.0.rkm1
-
cpe:2.3:o:asustor:data_master:4.1.0.rlq1
-
cpe:2.3:o:asustor:data_master:4.2.0.rc81
-
cpe:2.3:o:asustor:data_master:4.2.0.re71
-
cpe:2.3:o:asustor:data_master:4.2.1.rge2
-
cpe:2.3:o:asustor:data_master:4.2.2.ri61
-
cpe:2.3:o:asustor:data_master:4.2.3.rk91
-
cpe:2.3:o:asustor:data_master:4.2.4.rl82
-
cpe:2.3:o:asustor:data_master:4.2.5.rn33
-
cpe:2.3:o:asustor:data_master:4.2.6.ror2
-
cpe:2.3:o:asustor:data_master:4.2.6.rpi1
-
cpe:2.3:o:asustor:data_master:4.2.7.rr41
-
cpe:2.3:o:asustor:data_master:4.2.7.rrd1
-
cpe:2.3:o:asustor:data_master:4.3.0.rsb1
-
cpe:2.3:o:asustor:data_master:4.3.1.r6c1
-
cpe:2.3:o:asustor:data_master:4.3.1.r752
-
cpe:2.3:o:asustor:data_master:4.3.2.r9q2
-
cpe:2.3:o:asustor:data_master:4.3.3.rc92
-
cpe:2.3:o:asustor:data_master:4.3.3.rfk1
-
cpe:2.3:o:asustor:data_master:4.3.3.rh61
-
cpe:2.3:o:asustor:data_master:4.3.3.rjh1
-
cpe:2.3:o:asustor:data_master:4.3.3.rjl1
-
cpe:2.3:o:asustor:data_master:4.3.3.rkd2
-
cpe:2.3:o:asustor:data_master:4.3.3.rof1
-
cpe:2.3:o:asustor:data_master:5.0.0.ra82
-
cpe:2.3:o:asustor:data_master:5.0.0.rcg1
-
cpe:2.3:o:asustor:data_master:5.0.0.reo2
-
cpe:2.3:o:asustor:data_master:5.0.0.rfp3
-
cpe:2.3:o:asustor:data_master:5.0.0.rhn2
-
cpe:2.3:o:asustor:data_master:5.0.0.rin1
-
cpe:2.3:o:asustor:data_master:5.0.0.rjg2
-
cpe:2.3:o:asustor:data_master:5.0.0.rjl1
-
cpe:2.3:o:asustor:data_master:5.0.1.rkd2
-
cpe:2.3:o:asustor:data_master:5.1.0.rmm1
-
cpe:2.3:o:asustor:data_master:5.1.0.rn42
-
cpe:2.3:o:asustor:data_master:5.1.1.rci1