{"id":"CVE-2025-34248","title":"D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due to improper sanitization of the deleteBackupList parameter","summary":"D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due to improper sanitization of the deleteBackupList parameter. This can allow an authenticat…","severity":"none","cwe":["CWE-22"],"published":"2025-10-09","updated":"2026-10-08","sourceUpdated":"2026-10-08T13:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-34248","references":[{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10472","label":"disclosure@vulncheck.com"},{"url":"https://www.dlink.com/en/for-business/nuclias/nuclias-connect","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/dlink-nuclias-connect-directory-traversal-to-arbitrary-file-deletion","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.0065,"epssPercentile":0.49554,"ingestedAt":"2026-10-08T13:42:55.058Z","slug":"CVE-2025-34248","body":"## Overview\n\nD-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due to improper sanitization of the deleteBackupList parameter. This can allow an authenticated attacker to delete arbitrary files impacting the integrity and availability of the system.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}