CVE-2026-24934: An improper certificate validation vulnerability was found in ADM while querying an external server for the device's WAN IP address.
The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an external server for the device's WAN IP address. An unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) attack to spoof the response, leading the device to update its DDNS record with an incorrect IP address. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.1.RCI1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24934?
CVE-2026-24934 is categorized as a medium severity vulnerability due to improper certificate validation.
How do I fix CVE-2026-24934?
To fix CVE-2026-24934, update your ADM software to version 4.3.4 or later for affected versions.
Which versions are affected by CVE-2026-24934?
CVE-2026-24934 affects ADM versions from 4.1.0 to 4.3.3.ROF1 and 5.0.0 to 5.1.1.RCI1.
What impact does CVE-2026-24934 have on my device?
CVE-2026-24934 could allow an attacker to intercept sensitive information due to insecure certificate validation.
Is CVE-2026-24934 specific to a certain device?
Yes, CVE-2026-24934 specifically affects ADM software used in devices that query external servers for WAN IP addresses.