D-Link Nuclias Connect vulnerabilities
4 known vulnerabilities affecting d-link/nuclias_connect.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2025-34254MEDIUMCVSS 6.9≥ *, < 1.3.1.42025-10-16
CVE-2025-34254 [MEDIUM] CWE-204 CVE-2025-34254: D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulne
D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Login' endpoint returns distinct JSON responses depending on whether the supplied username is associated with an existing account. Because the responses differ in the `error.message`string value, an unauthenticated remote
cvelistv5nvd
CVE-2025-34253MEDIUMCVSS 5.1fixed in 1.3.1.42025-10-16
CVE-2025-34253 [MEDIUM] CWE-79 CVE-2025-34253: D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vuln
D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the 'Network' field when editing the configuration, creating a profile, and adding a network. An authenticated attacker can inject arbitrary JavaScript to be executed in the context of other users viewing the p
cvelistv5nvd
CVE-2025-34255MEDIUMCVSS 6.9≥ *, < 1.3.1.42025-10-16
CVE-2025-34255 [MEDIUM] CWE-204 CVE-2025-34255: D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulne
D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Forgot Password' endpoint returns distinct JSON responses depending on whether the supplied email address is associated with an existing account. Because the responses differ in the `data.exist` boolean value, an unauthent
cvelistv5nvd
CVE-2025-34248HIGHCVSS 7.2≥ *, < 1.3.1.42025-10-09
CVE-2025-34248 [HIGH] CWE-22 CVE-2025-34248: D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability withi
D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due to improper sanitization of the deleteBackupList parameter. This can allow an authenticated attacker to delete arbitrary files impacting the integrity and availability of the system.
cvelistv5nvd