CVE-2026-24936 is a critical improper input validation vulnerability (CWE-20) in ASUSTOR ADM versions 4.1.0 through 4.3.3.ROF1 and 5.0.0 through 5.1.1.RCI1. This flaw allows an unauthenticated remote attacker to write arbitrary data to any file on the system when a specific function is enabled during Active Directory domain joining. With a CVSS score of 9.8 (CRITICAL), the vulnerability has a network attack vector, low attack complexity, and no required privileges or user interaction, leading to complete system compromise (confidentiality, integrity, and availability). Currently, there is no public exploit intelligence, including Metasploit or Nuclei modules, and it has not been added to CISA's KEV catalog. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.1.0, <= 4.3.3.ROF1CPE match | cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:* | ||
>= 5.0.0, <= 5.1.1.RCI1CPE match | cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*:* | ||
>= 4.1.0.rhu2, <= 4.3.3.rof1CPE matchmatch criteria | cpe:2.3:o:asustor:data_master:*:*:*:*:*:*:*:* | ||
>= 5.0.0.ra82, < 5.1.2.re51CPE matchmatch criteria | cpe:2.3:o:asustor:data_master:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.