GHSA-32w9-6rwg-p96w · Severity: critical — A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability...
A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary code on the underlying operating system. This occurs due to insufficient validation of user-supplied input before it is passed to a system shell. Successful exploitation allows an attacker to achieve Remote Code Execution (RCE) and fully compromise the system. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RR42 as well as from ADM 5.0.0 through ADM 5.1.2.REO1.
Conclusion & alert: CVE-2026-6644 is rated Moderate Risk (58/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.36%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-01 | 0.32% | 0.36% | +0.04% |
| 2 | 2026-04-26 | 0.22% | 0.32% | +0.09% |
| 3 | 2026-04-23 | — | 0.22% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.4 | 4.0 | CRITICAL |
|
— | — | [email protected] |
| 9.1 | 3.1 | CRITICAL |
|
2.3 | 6.0 | [email protected] |
GHSA-32w9-6rwg-p96w · Severity: critical — A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| asustor | data_master | >= 4.1.0.rhu2, < 4.3.3.RR42 | cpe:2.3:o:asustor:data_master:*:*:*:*:*:*:*:* |
| asustor | data_master | >= 5.0.0.ra82, < 5.1.2.reo1 | cpe:2.3:o:asustor:data_master:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://https://www.asustor.com/security/security_advisory_detail?id=55 | Broken Link Vendor Advisory |
| https://uky007.github.io/CVE-2026-6644/ |