CVE-2025-13053: Asustor Data Master
Low severity, CVSS 3.7. EPSS: 0.1% chance of exploitation in the next 30 days.
When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the UPS server configuation. This issue affects ADM: from 4.1.0 through 4.3.3.RKD2, from 5.0.0 through 5.1.0.RN42.
Affected products
- Asustor Data Master: from 4.1.0.RHU2, before 4.3.3.ROF1 (fixed in 4.3.3.ROF1); from 5.0.0.ra82, before 5.1.1.RCI1 (fixed in 5.1.1.RCI1)
Published 2025-12-12. Last modified 2026-10-07.