CVE-2026-6643
- EPSS 0.47%
- Veröffentlicht 20.04.2026 06:34:27
- Zuletzt bearbeitet 22.04.2026 14:43:12
A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing user-controlled data directly to printf(). Due to the lack of PIE and Stack Canary protections, an aut...
CVE-2026-3179
- EPSS 0.49%
- Veröffentlicht 25.02.2026 06:16:27
- Zuletzt bearbeitet 26.02.2026 16:32:25
The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames containing path traversal sequences, causing the client to write file...
CVE-2026-3100
- EPSS 0.18%
- Veröffentlicht 25.02.2026 06:16:26
- Zuletzt bearbeitet 26.02.2026 16:33:43
The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP server using FTPES/FTPS. An improper validated TLS/SSL certificates allows a remote attacker can intercept network traffic to perform...
CVE-2026-24936
- EPSS 0.78%
- Veröffentlicht 03.02.2026 04:15:56
- Zuletzt bearbeitet 19.02.2026 17:39:07
When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI program allowing an unauthenticated remote attacker to write arbitrary data to any file on the system. By ...
CVE-2026-24935
- EPSS 0.14%
- Veröffentlicht 03.02.2026 03:15:53
- Zuletzt bearbeitet 19.02.2026 18:19:51
A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While subsequent access to device services requires additional authentication, a Man-in-the-Middle (MitM) attacker can intercept or red...
CVE-2026-24934
- EPSS 0.16%
- Veröffentlicht 03.02.2026 03:15:53
- Zuletzt bearbeitet 19.02.2026 18:18:18
The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an external server for the device's WAN IP address. An unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) attack to spoo...
CVE-2026-24933
- EPSS 0.2%
- Veröffentlicht 03.02.2026 03:15:53
- Zuletzt bearbeitet 19.02.2026 18:17:38
The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validation vulnerability allows an unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) at...
CVE-2026-24932
- EPSS 0.21%
- Veröffentlicht 03.02.2026 03:15:53
- Zuletzt bearbeitet 19.02.2026 18:16:57
The DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Although the connection uses HTTPS, an improper validated TLS/SSL certificates allows a remote attacker can intercept the communication ...
CVE-2025-13053
- EPSS 0.09%
- Veröffentlicht 12.12.2025 02:46:08
- Zuletzt bearbeitet 07.10.2026 20:10:01
When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack,...
CVE-2025-13052
- EPSS 0.18%
- Veröffentlicht 12.12.2025 02:30:35
- Zuletzt bearbeitet 07.10.2026 20:10:01
When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who can intercept network traffic between the SMTP client and server to execute a man-in-the-middle...