CVE-2025-34248

D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due to improper sanitization of the deleteBackupList parameter. This can allow an authenticated attacker to delete arbitrary files impacting the integrity and availability of the system.
CVSS

No CVSS.

Configurations

No configuration.

History

14 Oct 2025, 13:15

Type Values Removed Values Added
References
  • () https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10472 -

09 Oct 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-09 21:15

Updated : 2025-10-14 19:37


NVD link : CVE-2025-34248

Mitre link : CVE-2025-34248

CVE.ORG link : CVE-2025-34248


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')