Asustor ADM FTP Backup Improper TLS Certificate Validation Vulnerability Allowing Man-in-the-Middle Attacks

Vulnerability

A vulnerability exists in the FTP Backup feature on Asustor's ADM operating system, specifically in versions 4.1.0 prior to 4.3.3.ROF1 and 5.0.0 prior to 5.1.2.RE51. The issue arises because the application does not properly enforce strict TLS certificate verification when connecting to FTP servers via FTPES/FTPS. This improper validation allows remote attackers to intercept network traffic and conduct Man-in-the-Middle (MitM) attacks, potentially intercepting, modifying, or stealing sensitive information such as authentication credentials and backup data.

Impact

Exploitation of this vulnerability could lead to a Man-in-the-Middle attack, allowing interception, modification, or theft of sensitive information, including authentication credentials and backup data.

Remediation

Users can upgrade to Asustor ADM 5.1.2.REO1 or above to address this vulnerability. For those on ADM 4.1, 4.2, or 4.3, the vulnerability is still being addressed.

Added: Feb 25, 2026, 6:23 AM
Updated: Feb 25, 2026, 7:20 AM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
3.1
exploitability
4.8
remediation
7.7
relevance
3.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.