PT-2025-42529 · D Link · D-Link Nuclias Connect
Alex Williams
·
Published
2025-10-16
·
Updated
2025-10-16
·
CVE-2025-34255
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
D-Link Nuclias Connect versions 1.3.1.4 and earlier
Description
The application’s 'Forgot Password' endpoint exhibits a response discrepancy based on whether the provided email address exists in the system. The endpoint returns different JSON responses, specifically varying the
data.exist boolean value, allowing an unauthenticated remote attacker to enumerate valid email addresses and accounts on the server.Recommendations
Update to a version later than 1.3.1.4.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Nuclias Connect