Critical 9.2 Severity Path Traversal Flaw Compromises ASUSTOR FTP Backups
ID: 880378ca-7e34-539a-ac4e-ad68853fd5c2
STIX ID: report--880378ca-7e34-539a-ac4e-ad68853fd5c2
Feed Name: securityonline.info
ASUSTOR published an urgent advisory for critical FTP Backup vulnerabilities in ADM: CVE-2026-3100 (TLS/SSL certificate validation bypass enabling Man-in-the-Middle interception of credentials and backup data) and CVE-2026-3179 (path traversal via unsanitized FTP filenames, CVSS 9.2) affecting ADM 4.1.0–4.3.3.ROF1 and 5.0.0–5.1.2.RE51; ASUSTOR fixed the issues in ADM 5.1.2.REO1 and strongly urges administrators to update immediately to prevent data interception, modification, or arbitrary file writes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
