Back

HIGH

An improper certificate validation vulnerability was found in the FTP Backup on the ADM.

Published Feb 25, 2026

Description

The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP server using FTPES/FTPS. An improper validated TLS/SSL certificates allows a remote attacker can intercept network traffic to perform a Man-in-the-Middle (MitM) attack, which may intercept, modify, or obtain sensitive information such as authentication credentials and backup data. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.2.RE51.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ASUSTOR1
Published Feb 25, 2026
Updated Feb 27, 2026
Reserved Feb 24, 2026
CISA Vulnrichment
Updated Feb 25, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ASUSTOR1
Published Feb 25, 2026
Updated Feb 27, 2026
Exploited since n/a
EUVD-2026-8516