CVE-2026-3100 Details
Description
The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP server using FTPES/FTPS. An improper validated TLS/SSL certificates allows a remote attacker can intercept network traffic to perform a Man-in-the-Middle (MitM) attack, which may intercept, modify, or obtain sensitive information such as authentication credentials and backup data. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.2.RE51.
A vulnerability exists in the FTP Backup feature on Asustor's ADM operating system, specifically in versions 4.1.0 prior to 4.3.3.ROF1 and 5.0.0 prior to 5.1.2.RE51. The issue arises because the application does not properly enforce strict TLS certificate verification when connecting to FTP servers via FTPES/FTPS. This improper validation allows remote attackers to intercept network traffic and conduct Man-in-the-Middle (MitM) attacks, potentially intercepting, modifying, or stealing sensitive information such as authentication credentials and backup data.
Users can upgrade to Asustor ADM 5.1.2.REO1 or above to address this vulnerability. For those on ADM 4.1, 4.2, or 4.3, the vulnerability is still being addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.asustor.com/security/security_advisory_detail?id=53 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| asustor data master | >= 4.1.0.rhu2, <= 4.3.3.rof1 >= 5.0.0.ra82, < 5.1.2.reo1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 26, 2026 | Initial Analysis | [email protected] |
| Feb 25, 2026 | CVE Modified | [email protected] |
| Feb 25, 2026 | New CVE Received | [email protected] |