PT-2025-42527 · D Link · D-Link Nuclias Connect

Alex Williams

·

Published

2025-10-16

·

Updated

2025-10-17

·

CVE-2025-34253

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions D-Link Nuclias Connect versions 1.3.1.4 and earlier
Description The software contains a stored cross-site scripting (XSS) issue because of insufficient input validation of the Network field during configuration editing, profile creation, and network addition. A user with network access can inject JavaScript code that will be executed when other users view the profile. The affected API endpoint is not specified. The vulnerable parameter is Network.
Recommendations Update to a version of the software later than 1.3.1.4.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13179
CVE-2025-34253

Affected Products

D-Link Nuclias Connect