Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105324— An HTTP header injection vulnerability was found in the ADM

Quick assessment

Affected
ASUSTOR Inc. ADM
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ADM 的 start-page-loader.cgi 中存在 HTTP 头注入漏洞,允许未经身份验证的远程攻击者读取主机系统上的任意文件。攻击者可通过通过 state 参数发送包含注入头的精心构造的 HTTP 请求,利用底层 Web 服务器的 X-Sendfile 机制,在无需身份验证的情况下检索敏感文件。 受影响的版本包括:ADM 4.1.0 至 ADM 4.3.3.RWC1,以及 ADM 5.0.0 至 ADM 5.1.4.RL21。

CVSS 9.2 · Critical

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105324

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
An HTTP header injection vulnerability was found in the ADM
Source: CVE Program / CVE List V5
Vulnerability Description
An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter, the attacker can leverage the underlying web server's X-Sendfile mechanism to retrieve sensitive files without authentication. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RWC1 as well as from ADM 5.0.0 through ADM 5.1.4.RL21.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
HTTP头部中CRLF序列转义处理不恰当(HTTP响应分割)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ASUSTOR Inc. ADM 5.0.0 ~ 5.1.4.RL21 -

II. Public POCs for CVE-2026-105324

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
default-local-qwen3.6 · 10155 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-105324

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-105324 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-105324

No comments yet


Leave a comment