ASUSTOR has released a fix for a critical ADM vulnerability, CVE-2026-105324, which allows an unauthenticated remote attacker to read arbitrary files on an affected NAS via an HTTP header injection flaw. The issue carries a CVSS score of 9.2 (CVSSv4) and is described as a read-anything vulnerability that requires no login or user interaction.
The advisory notes that the flaw exists in the start-page-loader[.]cgi script and leverages the web server’s X-Sendfile feature to deliver files directly from disk, enabling attackers to retrieve sensitive host files without authentication.
The vulnerability affects ADM 4.x and 5.x release lines, specifically ADM 4.1.0 through ADM 4.3.3.RWC1 and ADM 5.0.0 through ADM 5.1.4.RL21. ASUSTOR recommends upgrading to ADM 5.1.4.RM62 or later on the 5.x branch, or ADM 4.3.3.RY62 or later on the 4.x branch. Until patched, users are advised to avoid exposing the ADM web interface to the internet and to access devices via a VPN.
The advisory notes that, as of the report, there were no confirmed exploits in the wild or public proof-of-concept, but the severity remains high given the unauthenticated nature and potential impact on exposed NAS devices.