Stack-based Buffer Overflow in Asustor VPN Clients
CVE-2026-6643
Key Information:
- Vendor
Asustor Inc.
- Status
- Vendor
- CVE Published:
- 20 April 2026
Badges
What is CVE-2026-6643?
A stack-based buffer overflow vulnerability exists in the VPN Clients on Asustor's ADM platform. This flaw results from the unbounded use of the sscanf() function and the direct incorporation of user-controlled data into printf() calls. The absence of protection mechanisms such as Position Independent Executables (PIE) and Stack Canaries allows authenticated remote attackers to exploit this vulnerability, enabling them to execute arbitrary code under the privileges of the web server user. Organizations utilizing affected versions of Asustor's VPN Clients should consider taking immediate steps to mitigate the risks linked with this vulnerability.
Affected Version(s)
ADM Linux 4.1.0 <= 4.3.3.RR42
ADM Linux 5.0.0 <= 5.1.2.REO1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
