Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical ASUSTOR NAS Security Flaw Enables Complete Device Takeover

A critical vulnerability affecting ASUSTOR Network Attached Storage (NAS) devices has been disclosed, which may allow unauthenticated attackers to gain full control of the affected systems.

A critical vulnerability affecting ASUSTOR Network Attached Storage (NAS) devices has been disclosed, which may allow unauthenticated attackers to gain full control of the affected systems.

Identified as CVE-2026-24936 , this flaw has a CVSS v4.0 base score of 9.5. It is found in the ASUSTOR Data Master (ADM) operating system, primarily affecting the process for joining an Active Directory (AD) Domain.

The issue is an improper input validation vulnerability within a specific CGI program. This flaw arises when a particular function is enabled as the NAS attempts to join an AD Domain. Due to inadequate input parameter validation, the system is vulnerable to exploitation.

An unauthenticated remote attacker can exploit this to bypass security controls and write arbitrary data to any file on the system, potentially overwriting critical system files or configuration settings. This can lead to a complete system compromise and grant root-level access to the attacker.

Identified as CVE-2026-24936 , this flaw has a CVSS v4.0 base score of 9.5.
Robert Langley · Thehackingpost

CVE ID: CVE-2026-24936 Severity: Critical CVSS v4.0 Score: 9.5 Vulnerability Type: Improper Input Validation / Arbitrary File Write

The vulnerability impacts two major branches of the ADM software. A patch is available for the ADM 5.x series, resolved in ADM 5.1.2.RE31. Users running ADM 5.0.0 through 5.1.1.RCI1 should upgrade immediately.

Advertisement

For users on the ADM 4.x branch, covering versions 4.1.0 through 4.3.3.ROF1, the status remains "Ongoing." Administrators should monitor ASUSTOR’s security advisories for updates and consider isolating these devices from the internet or disabling AD Domain joining features until a fix is available.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories