CVE-2025-13053Low· 3.7▾ SunlitWhen a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.10%
When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the UPS server configuation.
This issue affects ADM: from 4.1.0 through 4.3.3.RKD2, from 5.0.0 through 5.1.0.RN42.
data_master >= 4.1.0.RHU2, < 4.3.3.ROF1data_master >= 5.0.0.ra82, < 5.1.1.RCI1Upgrade past the affected range:
data_master 5.1.1.RCI1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-13052Medium· 5.9When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who can intercept network traffic between the SMTP client and server to execute a man-…
CVE-2025-36751NoneEncryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X
CVE-2025-15065Medium· 6.3Exposure of Sensitive Information to an Unauthorized Actor, Missing Encryption of Sensitive Data, Files or Directories Accessible to External Parties vulnerability in Kings Information & Network Co
CVE-2026-78860High· 7.8An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the storage of information in plaintext
CVE-2026-105179Low· 2.7A weakness has been identified in SourceCodester Drug Recommendation System 1.0
CVE-2025-59325High· 7.5CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline recovery of secrets and cryptographic details.