CVE-2026-24935
Severity CVSS v4.0:
MEDIUM
Type:
CWE-295
Improper Certificate Validation
Publication date:
03/02/2026
Last modified:
19/02/2026
Description
A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While subsequent access to device services requires additional authentication, a Man-in-the-Middle (MitM) attacker can intercept or redirect the NAT tunnel establishment. This could allow an attacker to disrupt service availability or facilitate further targeted attacks by acting as a proxy between the user and the device services.<br />
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.1.RCI1.
Impact
Base Score 4.0
6.30
Severity 4.0
MEDIUM
Base Score 3.x
5.60
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:asustor:data_master:*:*:*:*:*:*:*:* | 4.1.0.rhu2 (including) | 4.3.3.rof1 (including) |
| cpe:2.3:o:asustor:data_master:*:*:*:*:*:*:*:* | 5.0.0.ra82 (including) | 5.1.2.re51 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



