Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-105324: ADM lets attackers read files via crafted web request
CVE-2026-105324 · published 3 days ago
Summary
The ADM storage system (versions 4.1.0 through 4.3.3.RWC1 and 5.0.0 through 5.1.4.RL21) can be tricked into sending any file on the server back to a remote user. An attacker does not need a login and can use a specially formed web request to steal sensitive data. Update to the latest ADM release or apply the vendor’s patch to stop this behavior.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| asustor inc. | adm | <= 5.1.4.RL21 |
Original advisory text
An HTTP header injection vulnerability was found in the ADM
An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter, the attacker can leverage the underlying web server's X-Sendfile mechanism to retrieve sensitive files without authentication.
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RWC1 as well as from ADM 5.0.0 through ADM 5.1.4.RL21.
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RWC1 as well as from ADM 5.0.0 through ADM 5.1.4.RL21.
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Severity
9.2
Critical
Type
CWE-113Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
Timeline
Published7 Oct 2026
Updated8 Oct 2026
First seen7 Oct 2026
Track software like this
Free during beta