CVE-2026-24934: medium-severity vulnerability in ASUSTOR ADM
An improper certificate validation vulnerability was found in ADM while querying an external server for the device's WAN IP address.
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.3epss 0.2%
exploitation probability
0.2%top 94% of all CVEs
observed exploitation
nono source reports it
The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an external server for the device's WAN IP address. An unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) attack to spoof the response, leading the device to update its DDNS record with an incorrect IP address.
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.1.RCI1.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Affected products
ASUSTOR · ADMRelated CVEs — ASUSTOR ADM
In the same product, most dangerous first.
CVE-2023-2910HIGHA Command injection vulnerability was found on Printer service of ADMEPSS 1.6%CVE-2026-24936CRITICALAn improper input validation vulnerability was found in ADM while joining a AD Domain.EPSS 0.9%CVE-2026-3179CRITICALA path traversal vulnerability was found in the FTP Backup on the ADM.EPSS 0.8%CVE-2022-37398HIGHA stack-based buffer overflow vulnerability was found on ADMEPSS 0.7%CVE-2023-2909HIGHA Directory traversal vulnerability was found on EZ Sync service of ADMEPSS 0.7%CVE-2023-3697HIGHA Command injection vulnerability was found on Printer service of ADMEPSS 0.7%