PT-2026-5764 · Adm · Adm
Nuke
·
Published
2026-02-03
·
Updated
2026-02-19
·
CVE-2026-24932
CVSS v4.0
8.9
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ADM versions 4.1.0 through 4.3.3.ROF1
ADM versions 5.0.0 through 5.1.1.RCI1
Description
The DDNS update function does not properly validate the hostname of the DDNS server’s TLS/SSL certificate. Despite using HTTPS, improper validation allows a remote attacker to intercept communication, potentially performing a Man-in-the-Middle (MitM) attack. This could lead to the compromise of sensitive information during the DDNS updating process, including the user’s account email, MD5 hashed password, and device serial number.
Recommendations
Update ADM to a version later than 4.3.3.ROF1
Update ADM to a version later than 5.1.1.RCI1
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adm