When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who can intercept network traffic between the SMTP client and server to execute a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the SMTP. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RKD2 as well as from ADM 5.0.0 through ADM 5.1.0.RN42.
History

Fri, 12 Dec 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Asustor
Asustor adm
Vendors & Products Asustor
Asustor adm

Fri, 12 Dec 2025 03:15:00 +0000

Type Values Removed Values Added
Description When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who can intercept network traffic between the SMTP client and server to execute a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the SMTP. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RKD2 as well as from ADM 5.0.0 through ADM 5.1.0.RN42.
Title An improper certificates validation vulnerability was found in the Notification settings of ADM
Weaknesses CWE-295
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ASUSTOR1

Published: 2025-12-12T02:30:35.812Z

Updated: 2025-12-12T02:48:50.499Z

Reserved: 2025-11-12T10:01:36.262Z

Link: CVE-2025-13052

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-12T03:15:50.070

Modified: 2025-12-12T03:15:50.070

Link: CVE-2025-13052

cve-icon Redhat

No data.