PT-2025-42528 · D Link · D-Link Nuclias Connect

Alex Williams

·

Published

2025-10-16

·

Updated

2025-10-16

·

CVE-2025-34254

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions D-Link Nuclias Connect versions 1.3.1.4 and earlier
Description The application’s 'Login' endpoint, /Login, exhibits an observable response discrepancy. The endpoint returns different JSON responses based on whether the provided username is linked to an existing account. These differing responses, specifically in the error.message string, allow a remote attacker to enumerate valid usernames and accounts on the server without authentication.
Recommendations Versions prior to 1.3.1.4 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13177
CVE-2025-34254

Affected Products

D-Link Nuclias Connect