CVE-2026-3179
- EPSS 0.46%
- Veröffentlicht 25.02.2026 06:16:27
- Zuletzt bearbeitet 26.02.2026 16:32:25
The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames containing path traversal sequences, causing the client to write file...
CVE-2026-3100
- EPSS 0.06%
- Veröffentlicht 25.02.2026 06:16:26
- Zuletzt bearbeitet 26.02.2026 16:33:43
The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP server using FTPES/FTPS. An improper validated TLS/SSL certificates allows a remote attacker can intercept network traffic to perform...
CVE-2026-24936
- EPSS 0.11%
- Veröffentlicht 03.02.2026 04:15:56
- Zuletzt bearbeitet 19.02.2026 17:39:07
When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI program allowing an unauthenticated remote attacker to write arbitrary data to any file on the system. By ...
CVE-2026-24935
- EPSS 0.01%
- Veröffentlicht 03.02.2026 03:15:53
- Zuletzt bearbeitet 19.02.2026 18:19:51
A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While subsequent access to device services requires additional authentication, a Man-in-the-Middle (MitM) attacker can intercept or red...
CVE-2026-24934
- EPSS 0.01%
- Veröffentlicht 03.02.2026 03:15:53
- Zuletzt bearbeitet 19.02.2026 18:18:18
The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an external server for the device's WAN IP address. An unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) attack to spoo...
CVE-2026-24933
- EPSS 0.01%
- Veröffentlicht 03.02.2026 03:15:53
- Zuletzt bearbeitet 19.02.2026 18:17:38
The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validation vulnerability allows an unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) at...
CVE-2026-24932
- EPSS 0.01%
- Veröffentlicht 03.02.2026 03:15:53
- Zuletzt bearbeitet 19.02.2026 18:16:57
The DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Although the connection uses HTTPS, an improper validated TLS/SSL certificates allows a remote attacker can intercept the communication ...
CVE-2025-13053
- EPSS 0.01%
- Veröffentlicht 12.12.2025 02:46:08
- Zuletzt bearbeitet 28.01.2026 14:54:44
When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack,...
CVE-2025-13052
- EPSS 0.02%
- Veröffentlicht 12.12.2025 02:30:35
- Zuletzt bearbeitet 28.01.2026 14:53:53
When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who can intercept network traffic between the SMTP client and server to execute a man-in-the-middle...
CVE-2025-7699
- EPSS 0.05%
- Veröffentlicht 16.07.2025 09:41:12
- Zuletzt bearbeitet 16.07.2025 14:58:59
An improper access control vulnerability was found in the EZ Sync Manager of ADM, which allows authenticated users to copy arbitrary files from the server file system into their own EZSync folder. The vulnerability is due to a lack of authorization ...