CVE-2025-13053: high-severity vulnerability in ASUSTOR ADM
A missing encryption of sensitive data vulnerability was found in the UPS settings of ADM
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7epss 0.1%
exploitation probability
0.1%top 99% of all CVEs
observed exploitation
nono source reports it
When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the UPS server configuation.
This issue affects ADM: from 4.1.0 through 4.3.3.RKD2, from 5.0.0 through 5.1.0.RN42.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:L
Affected products
ASUSTOR · ADMRelated CVEs — ASUSTOR ADM
In the same product, most dangerous first.
CVE-2023-2910HIGHA Command injection vulnerability was found on Printer service of ADMEPSS 1.6%CVE-2026-24936CRITICALAn improper input validation vulnerability was found in ADM while joining a AD Domain.EPSS 0.9%CVE-2026-3179CRITICALA path traversal vulnerability was found in the FTP Backup on the ADM.EPSS 0.8%CVE-2022-37398HIGHA stack-based buffer overflow vulnerability was found on ADMEPSS 0.7%CVE-2023-2909HIGHA Directory traversal vulnerability was found on EZ Sync service of ADMEPSS 0.7%CVE-2023-3697HIGHA Command injection vulnerability was found on Printer service of ADMEPSS 0.7%