PT-2026-21876 · Asustor · Asustor Adm
Nuke
·
Published
2026-02-25
·
Updated
2026-02-26
·
CVE-2026-3100
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ASUSTOR ADM versions 4.1.0 through 4.3.3.ROF1
ASUSTOR ADM versions 5.0.0 through 5.1.2.RE51
Description
The FTP Backup feature does not properly validate TLS certificates when connecting to an FTP server using FTPES/FTPS. This improper validation allows a remote attacker to potentially intercept network traffic, enabling a Man-in-the-Middle (MitM) attack. Such an attack could lead to the interception, modification, or acquisition of sensitive information, including authentication credentials and backup data.
Recommendations
Update ASUSTOR ADM to a version later than 5.1.2.RE51.
Update ASUSTOR ADM to a version later than 4.3.3.ROF1.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asustor Adm