PT-2025-41465 · D Link · D-Link Nuclias Connect

Alex Williams

·

Published

2025-10-09

·

Updated

2025-10-10

·

CVE-2025-34248

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link Nuclias Connect versions prior to 1.3.1.4
Description The software contains a directory traversal issue in the /api/web/dnc/global/database/deleteBackup endpoint. This is due to insufficient input validation of the deleteBackupList parameter. A successful exploit by an authenticated attacker could lead to the deletion of arbitrary files, potentially compromising system integrity and availability.
Recommendations Update to version 1.3.1.4 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12883
CVE-2025-34248

Affected Products

D-Link Nuclias Connect