Description

D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due to improper sanitization of the deleteBackupList parameter. This can allow an authenticated attacker to delete arbitrary files impacting the integrity and availability of the system.

INFO

Published Date :

2025-10-09T20:43:53.064Z

Last Modified :

2025-10-10T14:30:14.216Z

Source :

VulnCheck
AFFECTED PRODUCTS

The following products are affected by CVE-2025-34248 vulnerability.

Vendors Products
D-link
  • Nuclias Connect
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-34248.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability