PT-2025-42529 · D Link · D-Link Nuclias Connect

Alex Williams

·

Published

2025-10-16

·

Updated

2025-10-16

·

CVE-2025-34255

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions D-Link Nuclias Connect versions 1.3.1.4 and earlier
Description The application’s 'Forgot Password' endpoint exhibits a response discrepancy based on whether the provided email address exists in the system. The endpoint returns different JSON responses, specifically varying the data.exist boolean value, allowing an unauthenticated remote attacker to enumerate valid email addresses and accounts on the server.
Recommendations Update to a version later than 1.3.1.4.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13178
CVE-2025-34255

Affected Products

D-Link Nuclias Connect