Command Injection Vulnerability in PPTP VPN Clients by ASUSTOR
CVE-2026-6644

9.4CRITICAL

Key Information:

Status
Vendor
CVE Published:
20 April 2026

What is CVE-2026-6644?

CVE-2026-6644 is a command injection vulnerability found in the Point-to-Point Tunneling Protocol (PPTP) VPN Clients utilized by Asustor's ADM (Asustor Data Master). This vulnerability arises from inadequate input validation of user-supplied data before it is processed by the system shell. Essentially, an administrative user could exploit this flaw to escape the constrained web environment of the application, thereby executing arbitrary code on the operating system beneath the application layer. This presents a significant risk to organizations employing Asustor's VPN functionalities, as successful exploitation could lead to a full system compromise, allowing unauthorized access and control over sensitive data and system operations.

Potential impact of CVE-2026-6644

  1. Remote Code Execution (RCE): The vulnerability enables an attacker to execute arbitrary code on the underlying operating system, which can result in the installation of malicious software, exfiltration of sensitive information, or other harmful activities.

  2. Full System Compromise: Successful exploitation of this vulnerability means that an attacker can gain complete control over the system. This level of access can lead to significant operational disruptions, data loss, or exploitation for further attacks within the organizational network.

  3. Increased Vulnerability to Ransomware and Other Attacks: With the ability to execute arbitrary code and gain system-level access, compromised systems may become gateways for ransomware deployment and other malicious activities, potentially affecting not only the immediate target but also connected networks and systems.

Affected Version(s)

ADM 4.1.0 <= 4.3.3.RR42

ADM 5.0.0 <= 5.1.2.REO1

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

uky
.