CVE-2026-6644Disclosure(asustor / data_master)

HIGHCVSS 9.1 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch asustor data_master systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary code on the underlying operating system. This occurs due to insufficient validation of user-supplied input before it is passed to a system shell. Successful exploitation allows an attacker to achieve Remote Code Execution (RCE) and fully compromise the system. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RR42 as well as from ADM 5.0.0 through ADM 5.1.2.REO1.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • data_master

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 24 mentions across 11 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 22 signals
  • Disclosure: 10 classified signals
  • Peaked 10d ago at 4 mentions (2026-04-20); latest day: 1
  • 24 total mentions across 11 days

Affected systems

Vendors
Products
data_master

Deep dive

Activity timeline24 mentions / 11d
01234Mentions · 2026-04-20: 4Mentions · 2026-04-21: 2Mentions · 2026-04-22: 1Mentions · 2026-04-24: 1Mentions · 2026-04-29: 1Mentions · 2026-04-30: 4Mentions · 2026-05-01: 2Mentions · 2026-05-07: 1Mentions · 2026-05-14: 4Mentions · 2026-05-20: 3Mentions · 2026-07-29: 1PoC Mentioned / Linked · 2026-04-29: 1PoC Mentioned / Linked · 2026-04-30: 4PoC Mentioned / Linked · 2026-05-07: 1PoC Mentioned / Linked · 2026-07-29: 1Exploit Tool / Code · 2026-04-30: 3Exploit Tool / Code · 2026-07-29: 1Active Exploitation · 2026-04-30: 1Patch / Workaround · 2026-04-21: 2Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-04-30: 3Patch / Workaround · 2026-05-01: 2Technical Details · 2026-04-20: 4Technical Details · 2026-04-21: 2Technical Details · 2026-04-22: 1Technical Details · 2026-04-29: 1Technical Details · 2026-04-30: 4Technical Details · 2026-05-01: 2Technical Details · 2026-05-07: 1Technical Details · 2026-05-14: 3Technical Details · 2026-05-20: 3Technical Details · 2026-07-29: 104-2004-2104-2204-2404-2904-3005-0105-0705-1405-2007-29
Signal classification5 categories
Disclosure
1041.7%
Patch
625.0%
PoC
520.8%
General
28.3%
Active Exploitation
14.2%
Referenced assets18 URLs
Classification over time
DateTotalLabels
2026-04-204
Disclosure4
2026-04-212
Patch2
2026-04-221
Patch1
2026-04-241
General1
2026-04-291
Patch1
2026-04-304
Active Exploitation1PoC3
2026-05-012
Patch2
2026-05-071
PoC1
2026-05-144
Disclosure3General1
2026-05-203
Disclosure3
2026-07-291
PoC1
Full discourse20 posts
  • Gray Hats@the_yellow_fall
    PoC

    Critical Root RCE (CVE-2026-6644) hits ASUSTOR ADM. With PoC code now public, 19,000 NAS devices are at risk. Update to ADM 5.1.3.RGO1 immediately. #ASUSTOR #NAS #CVE20266644 #RootRCE #PoC #CyberSecurity #PatchNow #InfoSec https://securityonline.info/asustor-adm-root-rce-poc-cve-2026-6644-public-disclosure/ https://t.co/sG7CCs5pxo

    Post summary

    The tweet announces a publicly available PoC for the critical root RCE CVE-2026-6644 in ASUSTOR ADM and urges users to apply the 5.1.3.RGO1 patch immediately.

    016033111.9K
    12.5K followersView on X
  • dbugs@ptdbugs
    PoC

    CVE-2026-6644: Command Injection in the ASUSTOR NAS VPN Client PT ID: PT-2026-33723 https://dbugs.ptsecurity.com/vulnerability/PT-2026-33723 A researcher analyzed the vulnerability CVE-2026-6644 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-6644) in the ASUSTOR VPN client and uncovered an interesting implementation detail. When creating a PPTP configuration, the vulnerable function "FUN_00403f21" in the "vpn.cgi" script correctly escaped the username and password before writing them to "pppd", but not the VPN server IP address. As a result, the server field became the source of the command injection. The error is notable because the most obvious user-controlled fields (credentials) were protected but another field was considered "safe", even though it accepted user input through the administration web interface. As a result, the code could be executed on the ASUSTOR Data Master (ADM) operating system with "root" privileges. ADM versions 4.1.0 through 4.3.3.RR42 and 5.0.0 through 5.1.2.REO1 are vulnerable. The researcher's Censys-based analysis showed that the issue affects 19,000 nodes. Article: https://nefariousplan.com/posts/asustor-vpn-escapes-credentials-not-server PoC: https://github.com/uky007/CVE-2026-6644 #dbugs_attacks

    Post summary

    The post supplies a Proof of Concept for CVE-2026‑6644 with technical details, but lacks evidence of active exploitation or patch information.

    00070498
    3.5K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 أصدرت ASUSTOR تصحيحًا حرجًا لثغرة حقن الأوامر التي تهدد مستخدمي نظام التشغيل ASUSTOR Data Master (ADM) أصدرت ASUSTOR تحذيرًا أمنيًا عاجلاً بشأن ثغرة حقن الأوامر عالية الخطورة CVE-2026-6644 في نظام التشغيل ASUSTOR Data Master (ADM). تسمح هذه الثغرة للمهاجمين بتنفيذ أوامر عشوائية على الأنظمة المتضررة. وقد تم تحديد خطورة عالية لهذه الثغرة، ويُنصح مستخدمي ADM بتطبيق التصحيحات الأمنية على الفور. — يُنصح بـتحديث نظام التشغيل ADM إلى أحدث إصدار. 🔗 للمزيد: https://securityonline.info/asustor-nas-adm-cve-2026-6644-critical-patch/

    Post summary

    ASUSTOR has issued a critical patch for CVE-2026-6644, a high‑severity command injection flaw in its Data Master OS, urging users to update immediately.

    00030763
    268 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『A command injection vulnerability was found in the PPTP VPN Clients on the ADM.』 『allows an administrative user to break out of the restricted web environment and execute arbitrary code on the underlying operating system.』 CVE-2026-6644 https://github.com/advisories/GHSA-32W9-6RWG-P96W

    Post summary

    A command injection flaw in PPTP VPN clients (CVE‑2026‑6644) permits administrative users to escape the web sandbox and run arbitrary OS commands; the vulnerability is disclosed with technical details but no PoC, exploit code, or evidence of active exploitation.

    01002605
    6.8K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-6644: A command injection vulnerability... ASUSTOR ADM's PPTP client lets admins shell-escape through command injection - classic CWE-78 with 9.4 CVSS means full N... https://zerodaysignal.com/vulnerability/CVE-2026-6644 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new command injection vulnerability (CVE‑2026‑6644) affecting ASUSTOR ADM’s PPTP client has been disclosed, highlighting its CWE‑78 classification and a high 9.4 CVSS score, but no active exploitation, Patch, or PoC is reported.

    01011104
    218 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    Attackers are exploiting CVE-2026-6644 in ASUSTOR ADM with a public PoC, allowing critical RCE. This could lead to full system compromise. Patch now to secure your network. #NerdieNews #CyberSecurity #InfoSec #Ransomware #Malware https://t.co/QDrIwHJYsL

    Post summary

    CVE-2026-6644 is actively exploited in ASUSTOR ADM devices via a public PoC that allows critical remote code execution, prompting immediate patching.

    1001053
    57 followersView on X
  • yousukezan@yousukezan
    Patch

    ASUSTORは、同社製NASのOSであるADM(ASUSTOR Data Master)のユーザーを脅かすコマンドインジェクションの脆弱性(CVE-2026-6644)について、重要なセキュリティパッチを公開した。 この脆弱性は、システムの深刻な乗っ取りにつながる可能性があるため、ADMユーザーは速やかにパッチを適用することが推奨される。 ASUSTOR製品では過去にも複数のクリティカルな脆弱性が報告されており、最新のセキュリティ情報への継続的な注意が求められる。 https://securityonline.info/asustor-nas-adm-cve-2026-6644-critical-patch/

    Post summary

    ASUSTOR released a critical patch for CVE-2026-6644, a command injection vulnerability that could allow full system takeover, and urges users to apply the fix promptly.

    010101.2K
    13.2K followersView on X
  • Criminal IP@CriminalIP_US
    Disclosure

    🗄️ CVE-2026-6644: When exposed NAS management becomes a command execution path ASUSTOR ADM’s PPTP VPN Client flaw allows authenticated attackers to break out of the web management environment and execute root-level commands. Criminal IP findings: • 14,537 ASUSTOR-related exposed assets • ADM management interfaces may be reachable online • Weak or reused admin credentials can turn post-auth RCE into real risk NAS exposure is not just a storage issue. It can become a direct path to data theft, ransomware, and internal compromise. 🔎 Full analysis https://www.criminalip.io/knowledge-hub/blog/34790 #CyberSecurity #ThreatIntelligence #AttackSurface #NAS #CVE

    Post summary

    The post announces CVE‑2026‑6644, detailing an RCE flaw in ASUSTOR ADM’s PPTP VPN Client that allows authenticated attackers to execute root commands, emphasizing the risk to exposed NAS management interfaces.

    01000300
    4.9K followersView on X
  • Criminal IP Japan@CriminalIP_JP
    Disclosure

    🖥️ ASUSTOR ADMにおけるコマンドインジェクション脆弱性(CVE-2026-6644)​ 本脆弱性はADMのPPTP VPN Client機能で発生する認証後のCommand Injectionであり、管理者権限取得後にroot権限で任意コマンド実行が可能となります。​ NASはバックアップや業務データ保存領域として利用されるケースが多く、侵害時にはファイル窃取、ランサムウェア、内部侵害拡大につながる可能性があります。​ 💡 Criminal IP観点の分析​ ▪ ASUSTOR関連の外部公開資産14,537件を確認​ ▪ HTTP/HTTPS管理インターフェースの外部公開を確認​ ▪ バナー情報からASUSTOR関連Webサービスの識別が可能​ 特に、外部公開されたADM管理ページと脆弱な認証情報が組み合わさる場合、管理者認証が実質的な攻撃障壁として機能しない可能性があります。​ 🔎 詳細分析はこちら​ https://www.criminalip.io/ja/knowledge-hub/blog/8854​ #サイバーセキュリティ #脅威インテリジェンス #NAS #ASUSTOR

    Post summary

    The entry announces a CVE-2026-6644 command‑injection flaw in ASUSTOR ADM's PPTP VPN Client, highlighting how compromised admin credentials could enable root‑level command execution, with potential for data theft and ransomware.

    00010168
    1.4K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-6644 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory A command injection vulnerability was found in the PPTP VPN Clients on the ADM.

    Post summary

    A critical command injection vulnerability (CVE-2026-6644) was disclosed for PPTP VPN Clients, with a CVSS score of 9.1 and no indicators of exploitation or mitigation provided.

    1000030
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-6644 (CVSS 9.1) — asustor data master. CVE: CVE-2026-6644 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The tweet announces CVE-2026-6644 with a CVSS 9.1 score and critical severity, but does not provide PoC, exploit code, active exploitation details, or patch information.

    1000035
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    References CVE: CVE-2026-6644 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    A critical advisory for CVE-2026-6644 is presented, listing its CVSS score (9.1) and severity level, but no PoC, exploitation details or mitigation steps are provided.

    1000026
    210 followersView on X
  • iototsecnews@iototsecnews
    PoC

    ASUSTOR ADM の 脆弱性 CVE-2026-6644 が FIX:root 権限での RCE と PoC のリリース https://iototsecnews.jp/2026/04/30/poc-disclosed-for-critical-root-asustor-adm-rce-flaw/ ASUSTOR NAS の ADM に存在する、コマンド・インジェクションの脆弱性 CVE-2026-6644 の原因は、 VPN 接続設定時に入力されるサーバ・アドレスの取り扱いにあります。具体的には、管理者が入力したアドレスをシステムが設定ファイルに書き込む際に、適切なサニタイズ/エスケープ処理が行われていませんでした。この入力値は、内部的にシェル経由で実行される仕組みになっているため、アドレス欄に特定の記号やコマンドを混ぜることで、 OS の最高権限である root 権限で任意の命令を実行できてしまう状態にあります。攻撃には管理者権限が必要ですが、初期設定のまま運用されているデバイスでは侵入が容易になるため注意が必要です。ご利用のチームは、ご注意ください。 #ADM #ASUSTOR #CVE20266644 #Vulnerability

    Post summary

    A proof‑of‑concept for CVE‑2026‑6644, a root‑elevated RCE via command injection in ASUSTOR ADM, has been released; no active exploitation or patch details are provided.

    01000131
    487 followersView on X
  • moton@moton
    PoC

    Exploit Exposed: Public PoC Disclosed for Critical Root RCE in ASUSTOR ADM (CVE-2026-6644) - https://securityonline.info/asustor-adm-root-rce-poc-cve-2026-6644-public-disclosure/

    Post summary

    A public PoC for the critical root RCE in ASUSTOR ADM (CVE‑2026‑6644) has been disclosed and linked, but no active exploitation or patch information is provided.

    10000117
    656 followersView on X
  • kokumօtօ@__kokumoto
    PoC

    ASUSTOR ADMの脆弱性CVE-2026-6644に対応するPoC(攻撃の概念実証コード)が公開された。PPTP VPNクライアント機能からのコマンドインジェクション。認証後の管理者が基盤システムを掌握可能。ADM 5.1.3.RGO1で修正済み。 https://securityonline.info/asustor-adm-root-rce-poc-cve-2026-6644-public-disclosure/

    Post summary

    A proof‑of‑concept revealing command injection via the PPTP VPN client in ASUSTOR ADM (CVE‑2026‑6644) has been published, and the vendor has patched the flaw in version 5.1.3.RGO1.

    00010918
    7.4K followersView on X
  • Criminal IP Korea@CriminalIP_KR
    Disclosure

    💉 ASUSTOR ADM 명령 주입 취약점 (CVE-2026-6644)​ 이번 이슈는 관리 인터페이스가 노출된 NAS가 얼마나 위험해질 수 있는지 보여주는 사례입니다.​ CVE-2026-6644는 ADM의 PPTP VPN Client 설정 과정에서 발생한 명령 주입 취약점으로, 관리자 권한을 확보한 공격자가 NAS에서 root 권한 명령 실행까지 이어갈 수 있습니다.​ Criminal IP 관점 인사이트 👇​ ✔ ASUSTOR 관련 자산 16,000건 이상 인터넷 노출​ ✔ 일부 자산에서 HTTP/HTTPS 직접 접근 확인​ ✔ 기본 페이지·웹 서비스 정보로 ASUSTOR 장비 식별 가능​ ​ 이 취약점은 사전 인증 원격 코드 실행은 아니지만, 외부 노출된 관리 페이지와 약한 계정이 결합되면 공격 장벽은 크게 낮아집니다.​ 📄전체 분석 확인하기​ https://www.criminalip.io/ko/knowledge-hub/blog/34764​ #사이버보안 #위협인텔리전스 #VPN #NAS

    Post summary

    It announces a command‑injection flaw in ASUSTOR's ADM that could lead to root privileges if the admin interface is exposed, but no exploitation evidence, PoC or patch is provided.

    0000082
    674 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-6644-asustor-data-master #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    Only a link and generic hashtags appear; the content lacks concrete details about the CVE.

    0000018
    210 followersView on X
  • selva@SelvaKtm2
    Patch

    CVE-2026-6644: Critical RCE Flaw Patched in ASUSTOR ADM NAS https://thecybrdef.com/cve-2026-6644-critical-rce-flaw-patched-in-asustor-adm-nas/ #CVE20266644 #ASUSTOR #NASsecurity #RemoteCodeExecution #CyberSecurity #RCE #VulnerabilityAlert #PatchNow #InfoSec #DataProtection #NetworkSecurity #StorageSecurity #CyberThreat #SecurityUpdate

    Post summary

    The post announces that a critical RCE flaw in ASUSTOR ADM NAS has been patched, with no PoC, exploit, or active exploitation evidence provided.

    0000036
    4 followersView on X
  • cybersecuritypath@cybrsecpath
    Patch

    CVE-2026-6644: Critical RCE Flaw Patched in ASUSTOR ADM NAS https://thecybrdef.com/cve-2026-6644-critical-rce-flaw-patched-in-asustor-adm-nas/ #CVE20266644 #ASUSTOR #NASsecurity #RemoteCodeExecution #CyberSecurity #RCE #VulnerabilityAlert #PatchNow #InfoSec #DataProtection #NetworkSecurity #StorageSecurity #CyberThreat #SecurityUpdate

    Post summary

    The article declares that CVE-2026-6644, a critical remote‑code‑execution flaw in ASUSTOR ADM NAS, has been patched, urging users to apply the update.

    0000029
    8 followersView on X
  • Ukycircle@UkyKnight
    Patch

    We discovered a Critical OS command injection vulnerability (CVE-2026-6644, CVSS v4.0: 9.4) in the PPTP VPN Client of ASUSTOR ADM. A patched firmware (ADM 5.1.3.RGO1) is now available. Users are strongly advised to update immediately. Details: https://uky007.github.io/CVE-2026-6644/ #InfoSec

    Post summary

    ASUSTOR ADM's PPTP VPN Client suffers from a critical OS command injection vulnerability (CVE-2026-6644, CVSS 9.4); a patched firmware (ADM 5.1.3.RGO1) is available and users are urged to update immediately.

    0000064
    11 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSasustordata_master---

Explore more