Command Injection Vulnerability in PPTP VPN Clients by ASUSTOR
CVE-2026-6644
What is CVE-2026-6644?
CVE-2026-6644 is a command injection vulnerability found in the Point-to-Point Tunneling Protocol (PPTP) VPN Clients utilized by Asustor's ADM (Asustor Data Master). This vulnerability arises from inadequate input validation of user-supplied data before it is processed by the system shell. Essentially, an administrative user could exploit this flaw to escape the constrained web environment of the application, thereby executing arbitrary code on the operating system beneath the application layer. This presents a significant risk to organizations employing Asustor's VPN functionalities, as successful exploitation could lead to a full system compromise, allowing unauthorized access and control over sensitive data and system operations.
Potential impact of CVE-2026-6644
-
Remote Code Execution (RCE): The vulnerability enables an attacker to execute arbitrary code on the underlying operating system, which can result in the installation of malicious software, exfiltration of sensitive information, or other harmful activities.
-
Full System Compromise: Successful exploitation of this vulnerability means that an attacker can gain complete control over the system. This level of access can lead to significant operational disruptions, data loss, or exploitation for further attacks within the organizational network.
-
Increased Vulnerability to Ransomware and Other Attacks: With the ability to execute arbitrary code and gain system-level access, compromised systems may become gateways for ransomware deployment and other malicious activities, potentially affecting not only the immediate target but also connected networks and systems.
Affected Version(s)
ADM 4.1.0 <= 4.3.3.RR42
ADM 5.0.0 <= 5.1.2.REO1
