CVE-2026-24933: An improper certificate validation vulnerability was found in ADM while sending HTTPS requests to the server.
The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validation vulnerability allows an unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) attack to intercept the cleartext communication, potentially leading to the exposure of sensitive user information, including account emails, MD5 hashed passwords, and device serial numbers.
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.1.RCI1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24933?
CVE-2026-24933 is considered a high-severity vulnerability due to its potential to allow attackers to perform man-in-the-middle attacks.
How do I fix CVE-2026-24933?
To fix CVE-2026-24933, ensure that the affected versions of ADM are updated to the latest version where proper SSL/TLS certificate validation is implemented.
Which versions of ADM are affected by CVE-2026-24933?
CVE-2026-24933 affects ADM versions from 4.1.0 to 4.3.3.ROF1 and from 5.0.0 to 5.1.1.RCI1.
What are the implications of CVE-2026-24933?
The implications of CVE-2026-24933 include the risk of data interception and unauthorized access to sensitive information due to insufficient SSL/TLS validation.
What is the nature of the vulnerability in CVE-2026-24933?
CVE-2026-24933 involves improper certificate validation which compromises the security of HTTPS requests sent by the ADM API communication component.