PT-2025-41465 · D Link · D-Link Nuclias Connect

Alex Williams

·

Publicado

2025-10-09

·

Atualizado

2025-10-10

·

CVE-2025-34248

CVSS v2.0

8.5

Alta

VetorAV:N/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link Nuclias Connect versions prior to 1.3.1.4
Description The software contains a directory traversal issue in the /api/web/dnc/global/database/deleteBackup endpoint. This is due to insufficient input validation of the deleteBackupList parameter. A successful exploit by an authenticated attacker could lead to the deletion of arbitrary files, potentially compromising system integrity and availability.
Recommendations Update to version 1.3.1.4 or later.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-12883
CVE-2025-34248

Produtos afetados

D-Link Nuclias Connect