CVE-2025-13053: Asustor Data Master

Low severity, CVSS 3.7. EPSS: 0.1% chance of exploitation in the next 30 days.

When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the UPS server configuation. This issue affects ADM: from 4.1.0 through 4.3.3.RKD2, from 5.0.0 through 5.1.0.RN42.

Affected products

  • Asustor Data Master: from 4.1.0.RHU2, before 4.3.3.ROF1 (fixed in 4.3.3.ROF1); from 5.0.0.ra82, before 5.1.1.RCI1 (fixed in 5.1.1.RCI1)

Published 2025-12-12. Last modified 2026-10-07.