Vulnerability Details CVE-2026-24935
A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While subsequent access to device services requires additional authentication, a Man-in-the-Middle (MitM) attacker can intercept or redirect the NAT tunnel establishment. This could allow an attacker to disrupt service availability or facilitate further targeted attacks by acting as a proxy between the user and the device services.
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.1.RCI1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 1.6%
CVSS Severity
CVSS v3 Score 5.6
Products affected by CVE-2026-24935
-
cpe:2.3:o:asustor:data_master:4.1.0.rhu2
-
cpe:2.3:o:asustor:data_master:4.1.0.rj72
-
cpe:2.3:o:asustor:data_master:4.1.0.rjd1
-
cpe:2.3:o:asustor:data_master:4.1.0.rkm1
-
cpe:2.3:o:asustor:data_master:4.1.0.rlq1
-
cpe:2.3:o:asustor:data_master:4.2.0.rc81
-
cpe:2.3:o:asustor:data_master:4.2.0.re71
-
cpe:2.3:o:asustor:data_master:4.2.1.rge2
-
cpe:2.3:o:asustor:data_master:4.2.2.ri61
-
cpe:2.3:o:asustor:data_master:4.2.3.rk91
-
cpe:2.3:o:asustor:data_master:4.2.4.rl82
-
cpe:2.3:o:asustor:data_master:4.2.5.rn33
-
cpe:2.3:o:asustor:data_master:4.2.6.ror2
-
cpe:2.3:o:asustor:data_master:4.2.6.rpi1
-
cpe:2.3:o:asustor:data_master:4.2.7.rr41
-
cpe:2.3:o:asustor:data_master:4.2.7.rrd1
-
cpe:2.3:o:asustor:data_master:4.3.0.rsb1
-
cpe:2.3:o:asustor:data_master:4.3.1.r6c1
-
cpe:2.3:o:asustor:data_master:4.3.1.r752
-
cpe:2.3:o:asustor:data_master:4.3.2.r9q2
-
cpe:2.3:o:asustor:data_master:4.3.3.rc92
-
cpe:2.3:o:asustor:data_master:4.3.3.rfk1
-
cpe:2.3:o:asustor:data_master:4.3.3.rh61
-
cpe:2.3:o:asustor:data_master:4.3.3.rjh1
-
cpe:2.3:o:asustor:data_master:4.3.3.rjl1
-
cpe:2.3:o:asustor:data_master:4.3.3.rkd2
-
cpe:2.3:o:asustor:data_master:4.3.3.rof1
-
cpe:2.3:o:asustor:data_master:5.0.0.ra82
-
cpe:2.3:o:asustor:data_master:5.0.0.rcg1
-
cpe:2.3:o:asustor:data_master:5.0.0.reo2
-
cpe:2.3:o:asustor:data_master:5.0.0.rfp3
-
cpe:2.3:o:asustor:data_master:5.0.0.rhn2
-
cpe:2.3:o:asustor:data_master:5.0.0.rin1
-
cpe:2.3:o:asustor:data_master:5.0.0.rjg2
-
cpe:2.3:o:asustor:data_master:5.0.0.rjl1
-
cpe:2.3:o:asustor:data_master:5.0.1.rkd2
-
cpe:2.3:o:asustor:data_master:5.1.0.rmm1
-
cpe:2.3:o:asustor:data_master:5.1.0.rn42
-
cpe:2.3:o:asustor:data_master:5.1.1.rci1