PT-2025-42528 · D Link · D-Link Nuclias Connect
Alex Williams
·
Published
2025-10-16
·
Updated
2025-10-16
·
CVE-2025-34254
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
D-Link Nuclias Connect versions 1.3.1.4 and earlier
Description
The application’s 'Login' endpoint,
/Login, exhibits an observable response discrepancy. The endpoint returns different JSON responses based on whether the provided username is linked to an existing account. These differing responses, specifically in the error.message string, allow a remote attacker to enumerate valid usernames and accounts on the server without authentication.Recommendations
Versions prior to 1.3.1.4 are affected.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Nuclias Connect