CVE-2025-13053: falha de alta gravidade em ASUSTOR ADM
A missing encryption of sensitive data vulnerability was found in the UPS settings of ADM
Publicada em
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7epss 0.1%
probabilidade de exploração
0.1%top 99% das CVEs
exploração observada
nãonenhuma fonte reporta
When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the UPS server configuation.
This issue affects ADM: from 4.1.0 through 4.3.3.RKD2, from 5.0.0 through 5.1.0.RN42.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:L
Produtos afetados
ASUSTOR · ADMCVEs relacionadas — ASUSTOR ADM
No mesmo produto, das mais perigosas para as menos.
CVE-2023-2910HIGHA Command injection vulnerability was found on Printer service of ADMEPSS 1.6%CVE-2026-24936CRITICALAn improper input validation vulnerability was found in ADM while joining a AD Domain.EPSS 0.9%CVE-2026-3179CRITICALA path traversal vulnerability was found in the FTP Backup on the ADM.EPSS 0.8%CVE-2022-37398HIGHA stack-based buffer overflow vulnerability was found on ADMEPSS 0.7%CVE-2023-2909HIGHA Directory traversal vulnerability was found on EZ Sync service of ADMEPSS 0.7%CVE-2023-3697HIGHA Command injection vulnerability was found on Printer service of ADMEPSS 0.7%