Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-105324: ADM lets attackers read files via crafted web request

CVE-2026-105324 · published 3 days ago
Summary

The ADM storage system (versions 4.1.0 through 4.3.3.RWC1 and 5.0.0 through 5.1.4.RL21) can be tricked into sending any file on the server back to a remote user. An attacker does not need a login and can use a specially formed web request to steal sensitive data. Update to the latest ADM release or apply the vendor’s patch to stop this behavior.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
asustor inc. adm <= 5.1.4.RL21
Original advisory text
An HTTP header injection vulnerability was found in the ADM
An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter, the attacker can leverage the underlying web server's X-Sendfile mechanism to retrieve sensitive files without authentication.
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RWC1 as well as from ADM 5.0.0 through ADM 5.1.4.RL21.
Fix within
Internet-facing 14 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker partial control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-113Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
Timeline
Published7 Oct 2026
Updated8 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-105324 · MITRE
Track software like this
Free during beta