Asustor Security Advisory AS-2025-010: ADM on Resolved Vulnerabilities
Multiple vulnerabilities have been reported to affect ADM NAS OS
This is a Press Release edited by StorageNewsletter.com on December 26, 2025 at 2:00 pmAsustor, Inc. had published a security advisory concerning multiple vulnerabilities reported to affect ADM NAS OS.
Date: 2025-12-22
Severity: Important
Status: Resolved
Statement
Multiple vulnerabilities have been reported to affect ADM:
- An improper certificates validation vulnerability was found in the Notification settings of ADM
- A missing encryption of sensitive data vulnerability was found in the UPS settings of ADM
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RKD2 as well as from ADM 5.0.0 through ADM 5.1.0.RN42
- The issues have been fixed on ADM 5.1.1.RCI1 and ADM 4.3.3.ROF1
Affected Products:
|
Product |
Severity |
Fixed Release Availability |
|---|---|---|
|
ADM 5.0 |
Important |
Upgrade to ADM 5.1.1.RCI1 or above |
|
ADM 4.3, ADM 4.2 and 4.1 |
Important |
Upgrade to ADM 4.3.3.ROF1 or above |
Detail:
- CVE-2025-13052
- Severity: High
- CVSS4 Base Score: 7.0
- CVSS4 Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:L
- When the user set the Notification’s sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who can intercept network traffic between the SMTP client and server to execute a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the SMTP. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RKD2 as well as from ADM 5.0.0 through ADM 5.1.0.RN42
- CVE-2025-13053
- Severity: High
- CVSS4 Base Score: 7.0
- CVSS4 Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:L
- When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the UPS server configuation. This issue affects ADM: from 4.1.0 through 4.3.3.RKD2, from 5.0.0 through 5.1.0.RN42
Reference:
Acknowledgement: Nuke
Revision:
|
Revision |
Date |
Description |
|---|---|---|
|
1 |
2025-12-08 |
Initial public release. |
|
2 |
2025-12-12 |
CVE ID (CVE-2025-13052, CVE-2025-13053) is assigned for the issue. |
|
3 |
2025-12-22 |
ADM 5.1.1.RCI1 and ADM 4.3.3.ROF1 have been released for fixing the issues. |












