CVE-2026-24934

LOW

ADM <4.3.3.ROF1, <5.1.1.RCI1 - Info Disclosure

Title source: llm
STIX 2.1

Description

The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an external server for the device's WAN IP address. An unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) attack to spoof the response, leading the device to update its DDNS record with an incorrect IP address. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.1.RCI1.

Scores

CVSS v3 3.7
EPSS 0.0001
EPSS Percentile 1.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (1)
asustor/data_master 4.1.0.rhu2 - 4.3.3.rof1
Published Feb 03, 2026
Tracked Since Feb 18, 2026