CVE-2025-34248

D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due to improper sanitization of the deleteBackupList parameter. This can allow an authenticated attacker to delete arbitrary files impacting the integrity and availability of the system.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2025-10-09 21:15

Updated : 2025-10-14 19:37


NVD link : CVE-2025-34248

Mitre link : CVE-2025-34248

CVE.ORG link : CVE-2025-34248


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')