CVE-2026-24934: Asustor Data Master
Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.
The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an external server for the device's WAN IP address. An unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) attack to spoof the response, leading the device to update its DDNS record with an incorrect IP address. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.1.RCI1.
Affected products
- Asustor Data Master: from 4.1.0.rhu2, up to and including 4.3.3.rof1; from 5.0.0.ra82, before 5.1.2.re51 (fixed in 5.1.2.re51)
Published 2026-02-03. Last modified 2026-06-17.