CVE-2025-13053: A missing encryption of sensitive data vulnerability was found in the UPS settings of ADM
When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the UPS server configuation.
This issue affects ADM: from 4.1.0 through 4.3.3.RKD2, from 5.0.0 through 5.1.0.RN42.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13053?
CVE-2025-13053 is considered a high-severity vulnerability due to the potential for man-in-the-middle attacks.
How do I fix CVE-2025-13053?
To mitigate CVE-2025-13053, ensure that the NAS configuration enforces strict TLS certificate verification.
What types of devices are affected by CVE-2025-13053?
CVE-2025-13053 affects specific versions of ADM software used in NAS devices.
What are the potential impacts of exploiting CVE-2025-13053?
Exploitation of CVE-2025-13053 can lead to unauthorized access to sensitive UPS control and status information.
Is there a workaround for CVE-2025-13053?
Currently, the only effective workaround for CVE-2025-13053 is to manually enforce TLS certificate validation in the settings.