
CVE-2026-105324 An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By send… https://www.cve.org/CVERecord?id=CVE-2026-105324
Signal is active with 3 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter, the attacker can leverage the underlying web server's X-Sendfile mechanism to retrieve sensitive files without authentication. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RWC1 as well as from ADM 5.0.0 through ADM 5.1.4.RL21.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

CVE-2026-105324 An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By send… https://www.cve.org/CVERecord?id=CVE-2026-105324

🚨 Critical vulnerabilities target ASUSTOR ADM (CVE-2026-105324) and ASUS routers (CVE-2026-19396), while an Apache ActiveMQ Artemis session hijacking PoC hits GitHub. Plus, a major court breach compromises data for over 1M people in Arizona. #threatintel https://panopticon.pranithjain.qzz.io/threatintel/telegram?tab=firehose

Critical ASUSTOR ADM vulnerability CVE-2026-105324 (CVSS 9.2) allows unauthenticated arbitrary file read on NAS devices. Update ADM now. #ASUSTOR #ADM #NAS #CVE2026105324 #FileRead #HeaderInjection #DataProtection #Vulnerability https://securityonline.info/asustor-adm-vulnerability-cve-2026-105324/