PT-2025-42527 · D Link · D-Link Nuclias Connect

Alex Williams

·

Publicado

2025-10-16

·

Atualizado

2025-10-17

·

CVE-2025-34253

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions D-Link Nuclias Connect versions 1.3.1.4 and earlier
Description The software contains a stored cross-site scripting (XSS) issue because of insufficient input validation of the Network field during configuration editing, profile creation, and network addition. A user with network access can inject JavaScript code that will be executed when other users view the profile. The affected API endpoint is not specified. The vulnerable parameter is Network.
Recommendations Update to a version of the software later than 1.3.1.4.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-13179
CVE-2025-34253

Produtos afetados

D-Link Nuclias Connect