CVE-2026-3100: An improper certificate validation vulnerability was found in the FTP Backup on the ADM.
The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP server using FTPES/FTPS. An improper validated TLS/SSL certificates allows a remote attacker can intercept network traffic to perform a Man-in-the-Middle (MitM) attack, which may intercept, modify, or obtain sensitive information such as authentication credentials and backup data. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.ROF1 as well as from ADM 5.0.0 through ADM 5.1.2.RE51.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3100?
CVE-2026-3100 is classified as a moderate severity vulnerability due to its potential exposure to sniffing attacks.
How do I fix CVE-2026-3100?
To fix CVE-2026-3100, you should upgrade ASUSTOR ADM to version 5.1.3 or later, which addresses the improper certificate validation.
What systems are affected by CVE-2026-3100?
CVE-2026-3100 affects ASUSTOR ADM versions from 4.1.0 to 4.3.3.ROF1 and from 5.0.0 to 5.1.2.RE51.
What type of attack can exploit CVE-2026-3100?
CVE-2026-3100 can be exploited in sniffing attacks due to improper certificate validation.
Is there a workaround for CVE-2026-3100?
Currently, the best mitigation for CVE-2026-3100 is to upgrade the software, as no effective workaround is available.