CVE-2026-3179
- EPSS 0.46%
- Veröffentlicht 25.02.2026 06:16:27
- Zuletzt bearbeitet 26.02.2026 16:32:25
The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames containing path traversal sequences, causing the client to write file...
CVE-2026-3100
- EPSS 0.06%
- Veröffentlicht 25.02.2026 06:16:26
- Zuletzt bearbeitet 26.02.2026 16:33:43
The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP server using FTPES/FTPS. An improper validated TLS/SSL certificates allows a remote attacker can intercept network traffic to perform...
CVE-2026-24936
- EPSS 0.11%
- Veröffentlicht 03.02.2026 04:15:56
- Zuletzt bearbeitet 19.02.2026 17:39:07
When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI program allowing an unauthenticated remote attacker to write arbitrary data to any file on the system. By ...
CVE-2026-24935
- EPSS 0.01%
- Veröffentlicht 03.02.2026 03:15:53
- Zuletzt bearbeitet 19.02.2026 18:19:51
A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While subsequent access to device services requires additional authentication, a Man-in-the-Middle (MitM) attacker can intercept or red...
CVE-2026-24934
- EPSS 0.01%
- Veröffentlicht 03.02.2026 03:15:53
- Zuletzt bearbeitet 19.02.2026 18:18:18
The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an external server for the device's WAN IP address. An unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) attack to spoo...
CVE-2026-24933
- EPSS 0.01%
- Veröffentlicht 03.02.2026 03:15:53
- Zuletzt bearbeitet 19.02.2026 18:17:38
The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validation vulnerability allows an unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) at...
CVE-2026-24932
- EPSS 0.01%
- Veröffentlicht 03.02.2026 03:15:53
- Zuletzt bearbeitet 19.02.2026 18:16:57
The DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Although the connection uses HTTPS, an improper validated TLS/SSL certificates allows a remote attacker can intercept the communication ...
CVE-2025-13053
- EPSS 0.01%
- Veröffentlicht 12.12.2025 02:46:08
- Zuletzt bearbeitet 28.01.2026 14:54:44
When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack,...
CVE-2025-13052
- EPSS 0.02%
- Veröffentlicht 12.12.2025 02:30:35
- Zuletzt bearbeitet 28.01.2026 14:53:53
When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who can intercept network traffic between the SMTP client and server to execute a man-in-the-middle...
CVE-2023-4475
- EPSS 0.07%
- Veröffentlicht 22.08.2023 19:16:41
- Zuletzt bearbeitet 21.11.2024 08:35:14
An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file renaming feature to move files to unintended directories. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below a...