Vulnerability Details CVE-2026-3100
The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP server using FTPES/FTPS. An improper validated TLS/SSL certificates allows a remote attacker can intercept network traffic to perform a Man-in-the-Middle (MitM) attack, which may intercept, modify, or obtain sensitive information such as authentication credentials and backup data.
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.2.RE51.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.3%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-3100
-
cpe:2.3:o:asustor:data_master:4.1.0.rhu2
-
cpe:2.3:o:asustor:data_master:4.1.0.rj72
-
cpe:2.3:o:asustor:data_master:4.1.0.rjd1
-
cpe:2.3:o:asustor:data_master:4.1.0.rkm1
-
cpe:2.3:o:asustor:data_master:4.1.0.rlq1
-
cpe:2.3:o:asustor:data_master:4.2.0.rc81
-
cpe:2.3:o:asustor:data_master:4.2.0.re71
-
cpe:2.3:o:asustor:data_master:4.2.1.rge2
-
cpe:2.3:o:asustor:data_master:4.2.2.ri61
-
cpe:2.3:o:asustor:data_master:4.2.3.rk91
-
cpe:2.3:o:asustor:data_master:4.2.4.rl82
-
cpe:2.3:o:asustor:data_master:4.2.5.rn33
-
cpe:2.3:o:asustor:data_master:4.2.6.ror2
-
cpe:2.3:o:asustor:data_master:4.2.6.rpi1
-
cpe:2.3:o:asustor:data_master:4.2.7.rr41
-
cpe:2.3:o:asustor:data_master:4.2.7.rrd1
-
cpe:2.3:o:asustor:data_master:4.3.0.rsb1
-
cpe:2.3:o:asustor:data_master:4.3.1.r6c1
-
cpe:2.3:o:asustor:data_master:4.3.1.r752
-
cpe:2.3:o:asustor:data_master:4.3.2.r9q2
-
cpe:2.3:o:asustor:data_master:4.3.3.rc92
-
cpe:2.3:o:asustor:data_master:4.3.3.rfk1
-
cpe:2.3:o:asustor:data_master:4.3.3.rh61
-
cpe:2.3:o:asustor:data_master:4.3.3.rjh1
-
cpe:2.3:o:asustor:data_master:4.3.3.rjl1
-
cpe:2.3:o:asustor:data_master:4.3.3.rkd2
-
cpe:2.3:o:asustor:data_master:4.3.3.rof1
-
cpe:2.3:o:asustor:data_master:5.0.0.ra82
-
cpe:2.3:o:asustor:data_master:5.0.0.rcg1
-
cpe:2.3:o:asustor:data_master:5.0.0.reo2
-
cpe:2.3:o:asustor:data_master:5.0.0.rfp3
-
cpe:2.3:o:asustor:data_master:5.0.0.rhn2
-
cpe:2.3:o:asustor:data_master:5.0.0.rin1
-
cpe:2.3:o:asustor:data_master:5.0.0.rjg2
-
cpe:2.3:o:asustor:data_master:5.0.0.rjl1
-
cpe:2.3:o:asustor:data_master:5.0.1.rkd2
-
cpe:2.3:o:asustor:data_master:5.1.0.rmm1
-
cpe:2.3:o:asustor:data_master:5.1.0.rn42
-
cpe:2.3:o:asustor:data_master:5.1.1.rci1