Description
A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to enumerate valid usernames and their associated privilege roles. The issue is triggered by modifying a parameter within requests sent to the /nasapi endpoint.
INFO
Published Date :
2026-04-20T00:00:00.000Z
Last Modified :
2026-04-20T16:54:28.824Z
Source :
mitre
AFFECTED PRODUCTS
The following products are affected by CVE-2025-66954 vulnerability.
No data.
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-66954.
| URL | Resource |
|---|---|
| https://github.com/DBmonster19/CVE-2025-66954 |
|