CVE-2025-34248
Last modified
CVE-2025-34248 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due to improper sanitization of the deleteBackupList parameter. This can allow an authenticated attacker to delete arbitrary files impacting the integrity and availability of the system.. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due to improper sanitization of the deleteBackupList parameter. This can allow an authenticated attacker to delete arbitrary files impacting the integrity and availability of the system.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-34248?
How severe is CVE-2025-34248?
How do I fix CVE-2025-34248?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-34242Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQ…6.5
- CVE-2025-34243Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQ…6.5
- CVE-2025-34244Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQ…6.5
- CVE-2025-34245Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQ…6.5
- CVE-2025-34246Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQ…6.5
- CVE-2025-34247Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQ…6.5
- CVE-2025-34249Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-3425The IntelliSpace portal application utilizes .NET Remoting f…7.3
- CVE-2025-34250Rejected reason: This CVE ID was rejected because it was res…
- CVE-2025-34251Tesla Telematics Control Unit (TCU) firmware prior to v2025.…8.6
- CVE-2025-34252Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-34253D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain …5.4
Are you affected by CVE-2025-34248?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
