CVE-2026-24935
Unknown Unknown - Not Provided

SSL/TLS Validation Bypass in ADM NAT Module Enables MitM Attack

Vulnerability report for CVE-2026-24935, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-02-03

Last updated on: 2026-02-19

Assigner: ASUSTOR, Inc.

Description

A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While subsequent access to device services requires additional authentication, a Man-in-the-Middle (MitM) attacker can intercept or redirect the NAT tunnel establishment. This could allow an attacker to disrupt service availability or facilitate further targeted attacks by acting as a proxy between the user and the device services. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.1.RCI1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-02-03
Last Modified
2026-02-19
Generated
2026-07-26
AI Q&A
2026-02-03
EPSS Evaluated
2026-07-25
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
asustor data_master From 4.1.0.rhu2 (inc) to 4.3.3.rof1 (inc)
asustor data_master From 5.0.0.ra82 (inc) to 5.1.2.re51 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a third-party NAT traversal module that does not properly validate SSL/TLS certificates when connecting to the signaling server. As a result, a Man-in-the-Middle (MitM) attacker can intercept or redirect the NAT tunnel establishment process. Although further authentication is required to access device services, the attacker could disrupt service availability or act as a proxy to facilitate additional targeted attacks between the user and the device services.

Detection Guidance

I don't know

Impact Analysis

The vulnerability can allow an attacker to intercept or redirect the NAT tunnel establishment, potentially disrupting service availability. Additionally, by acting as a proxy between the user and device services, the attacker could facilitate further targeted attacks, compromising the security and reliability of the affected device services.

Compliance Impact

I don't know

Mitigation Strategies

I don't know

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-24935. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart