CVE-2025-13052 - CVE House
Back to Database
Status published High CVE-2025-13052

An improper certificates validation vulnerability was found in the Notification settings of ADM

Vulnerability Description

When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who can intercept network traffic between the SMTP client and server to execute a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the SMTP. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RKD2 as well as from ADM 5.0.0 through ADM 5.1.0.RN42.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13052

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Nuke

Affected Vendor

Affected Software

ADM
Vulnerable Versions:
4.1.0, 5.0.0

Timeline

Official Publish: December 12th, 2025
Last Modified: December 12th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)