D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due to improper sanitization of the deleteBackupList parameter. This can allow an authenticated attacker to delete arbitrary files impacting the integrity and availability of the system.
CVSS
No CVSS.
References
Configurations
No configuration.
History
14 Oct 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
09 Oct 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-10-09 21:15
Updated : 2025-10-14 19:37
NVD link : CVE-2025-34248
Mitre link : CVE-2025-34248
CVE.ORG link : CVE-2025-34248
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')