CVE-2026-105324
An HTTP header injection vulnerability was found in the ADM
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter, the attacker can leverage the underlying web server's X-Sendfile mechanism to retrieve sensitive files without authentication. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RWC1 as well as from ADM 5.0.0 through ADM 5.1.4.RL21.
| CWE | CWE-113 |
| Vendor | asustor inc. |
| Product | adm |
| Published | Oct 7, 2026 |
| Last Updated | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for asustor inc. adm
Be the first to know when new unknown vulnerabilities affecting asustor inc. adm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
ASUSTOR Inc. / ADM
5.0.0 โค 5.1.4.RL21 4.1.0 โค 4.3.3.RWC1
References
Credits
๐ Benjamin Harris of watchTowr