CVE-2025-34248EPSS p49.7%
CVE-2025-34248CVE-2025-34248
Description
D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due to improper sanitization of the deleteBackupList parameter. This can allow an authenticated attacker to delete arbitrary files impacting the integrity and availability of the system.
Scoring
| EPSS | 0.65% probability of exploitation · percentile 49.7% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-08 |