CVE-2026-24934
Unknown
Unknown - Not Provided
Insecure DDNS HTTP/SSL Validation Enables MitM Attack in ADM
Publication date: 2026-02-03
Last updated on: 2026-02-19
Assigner: ASUSTOR, Inc.
Description
Description
The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an external server for the device's WAN IP address. An unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) attack to spoof the response, leading the device to update its DDNS record with an incorrect IP address.
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.1.RCI1.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| asustor | data_master | From 4.1.0.rhu2 (inc) to 4.3.3.rof1 (inc) |
| asustor | data_master | From 5.0.0.ra82 (inc) to 5.1.2.re51 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-295 | The product does not validate, or incorrectly validates, a certificate. |