← Vulnerability feed

Vulnerability record · CVE-2026-24933 · published 3 February 2026

CVE-2026-24933: Asustor data master improper certificate validation vulnerability

AAsustor · Data Master

The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validation vulnerability allows an unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) attack to intercept the cleartext communication, potentially leading to the exposure of sensitive user information, including account emails, MD5 hashed passwords, and device serial numbers. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.1.RCI1.

8.9 CVSS 4.0 High EPSS 0.21% · top 89.7% CWE-295 · Improper certificate validation
8.9CVSS 4.0 base score
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validation vulnerability allows an unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) attack to intercept the cleartext communication, potentially leading to the exposure of sensitive user information, including account emails, MD5 hashed passwords, and device serial numbers. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.1.RCI1.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-24933 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-12313Asustor data master os command injection vulnerabilityOS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity…EPSS 4.4%9.5CVE-2026-24936Asustor data master improper input validation vulnerabilityWhen a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI progr…EPSS 0.81%9.4CVE-2026-6644Asustor data master os command injection vulnerabilityA command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the r…EPSS 2.1%9.2CVE-2026-3179Asustor data master path traversal vulnerabilityThe FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MI…EPSS 0.77%8.9CVE-2026-24932Asustor data master improper certificate validation vulnerabilityThe DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Although the connection uses HTTPS,…EPSS 0.21%8.8CVE-2023-2910Asustor data master command injection vulnerabilityImproper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Ma…EPSS 1.6%8.8CVE-2023-3697Asustor data master path traversal vulnerabilityPrinter service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and …EPSS 0.66%8.8CVE-2018-12307Asustor data master os command injection vulnerabilityOS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "name" POST parameter.EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2026-24933), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.