216.73.216.226

CVE-2026-24933

· Published 03/02/2026 03:15 · Modified 03/02/2026 16:44

Labels: CVE-2026-24933 2026-02-03CVE-2026-24933CWE-295[email protected]

Essential information

Published
03/02/2026 03:15
Modified
03/02/2026 16:44
Author
Creator
CVSS
8.9 HIGH (v3) 8.9 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validation vulnerability allows an unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) attack to intercept the cleartext communication, potentially leading to the exposure of sensitive user information, including account emails, MD5 hashed passwords, and device serial numbers. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.1.RCI1.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
asustor / adm cpe:2.3:a:asustor:adm:4.1.0-4.3.3.ROF1:*:*:*:*:*:*:*
asustor / adm cpe:2.3:a:asustor:adm:5.0.0-5.1.1.RCI1:*:*:*:*:*:*:*

References