External risk intelligence

ADM HTTP Header Injection Vulnerability Allows Arbitrary File Read

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-105324

The vulnerability resides in a CGI script within an ADM (ASUSTOR Data Master) web interface. NAS devices running this software are frequently deployed as internet-facing management portals, and the vulnerability is accessible to unauthenticated remote attackers via standard HTTP requests.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An HTTP header injection vulnerability in ADM's start-page-loader.cgi could allow attackers to read sensitive files from the host system. This issue affects certain versions of ADM and is accessible remotely without authentication.

  • Unauthenticated attackers can read sensitive files.
  • Affects ADM systems, potentially internet-facing.
  • Confirm relevance and check system exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit a vulnerability in the ADM web interface by sending a specially crafted HTTP request. This request leverages the `state` parameter to inject malicious headers, which in turn tricks the web server's X-Sendfile mechanism into reading and returning arbitrary files from the host system. This allows the attacker to access sensitive information without needing any credentials.

  • Attacker can send malicious HTTP request.
  • Vulnerability is triggered via the `state` parameter.
  • Risk is reading arbitrary files from the host.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated remote attacker could read arbitrary files on the host system by sending a crafted HTTP request. This is possible when the underlying web server's X-Sendfile mechanism is leveraged via the `state` parameter.

  • Arbitrary host system files.
  • Crafted HTTP request with injected headers.
  • Disclosure of sensitive host system files.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in ADM's start-page-loader.cgi, allowing unauthenticated remote attackers to read arbitrary files, likely impacts system owners and platform teams responsible for the ADM deployment. The first practical step is to identify all ADM systems, determine their exposure to the internet, and confirm their business criticality to prioritize remediation efforts.

  • System owners must own the fix.
  • Verify internet-facing ADM deployments.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ADM and what does it do?

ADM stands for ASUSTOR Data Master. It is the web-based operating system used to manage ASUSTOR Network Attached Storage (NAS) devices. These devices act as centralized storage servers for homes and businesses, allowing users to store, backup, and share files across a network.

How does this CVE-2026-105324 vulnerability work?

This is an HTTP header injection issue (CWE-113). The vulnerability exists in a specific script, start-page-loader.cgi. By sending a malicious request, an attacker can manipulate headers to trick the web server into using its X-Sendfile feature, which then improperly serves files from the host system back to the attacker.

Do I need to be logged into the NAS for this to trigger?

No. The vulnerability is unauthenticated, meaning an attacker does not need a username or password to attempt it. The bug is specifically triggered by sending a crafted HTTP request that targets the 'state' parameter. Legitimate use of the web interface for standard file management does not trigger the vulnerability.

Is my device at risk if it is not reachable from the internet?

Halo Surface Signal indicates that this vulnerability is particularly concerning for devices configured as internet-facing management portals. If your ADM device is restricted to internal-only network access and not exposed to the public internet, the attack surface is significantly reduced, though internal threats may still exist.

What should I do first if I run ADM?

Begin by identifying all ADM devices in your environment and verifying their current version against the affected releases (4.1.0 through 4.3.3.RWC1 or 5.0.0 through 5.1.4.RL21). Confirm whether these devices are accessible from the internet. Once you have an inventory, prioritize patching any exposed systems and restrict external access until updates are applied.

References