CVE-2025-34253 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

D-Link Nuclias Connect firmware versions
Medium CVSS: 5.1

CVE-2025-34253

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the 'Network' field when editing the configuration, creating a profile, and adding a network. An authenticated attacker can inject arbitrary JavaScript to be executed in the context of other users viewing the profile entry. NOTE: D-Link states that a fix is under development.
Vendor
Dlink
Product
Nuclias Connect
CWE
CWE-79
Yayın Tarihi
2025-10-16 19:15:32
Güncelleme
2025-10-30 16:11:40
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar