logo

Critical 9.2 Severity Path Traversal Flaw Compromises ASUSTOR FTP Backups

ID: 880378ca-7e34-539a-ac4e-ad68853fd5c2

STIX ID: report--880378ca-7e34-539a-ac4e-ad68853fd5c2

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-25

Date Updated: 2026-04-23

Author: Ddos

...
...

ASUSTOR published an urgent advisory for critical FTP Backup vulnerabilities in ADM: CVE-2026-3100 (TLS/SSL certificate validation bypass enabling Man-in-the-Middle interception of credentials and backup data) and CVE-2026-3179 (path traversal via unsanitized FTP filenames, CVSS 9.2) affecting ADM 4.1.0–4.3.3.ROF1 and 5.0.0–5.1.2.RE51; ASUSTOR fixed the issues in ADM 5.1.2.REO1 and strongly urges administrators to update immediately to prevent data interception, modification, or arbitrary file writes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.