CVE-2026-105324

CVE-2026-105324 published: An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter, the attacker can le...

View full NVD advisory → ← Back to CVE watch