CVE-2026-105324
9.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Summary
An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter, the attacker can leverage the underlying web server's X-Sendfile mechanism to retrieve sensitive files without authentication. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RWC1 as well as from ADM 5.0.0 through ADM 5.1.4.RL21.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ASUSTOR Inc. | ADM | 5.0.0 <= 5.1.4.RL21 | affected |
| ASUSTOR Inc. | ADM | 4.1.0 <= 4.3.3.RWC1 | affected |
Weaknesses
- CWE-113: CWE-113 Improper neutralization of CRLF sequences in HTTP headers ('HTTP Request/Response splitting')
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.