{"id":"CVE-2025-70820","title":"Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.","summary":"Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.","severity":"low","cvss":3.5,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-36"],"vendor":"Zettlab","product":"D6 Ultra","affected":["d6_ultra < 1.7.0"],"published":"2026-09-13","updated":"2026-09-15","sourceUpdated":"2026-09-15T18:17:12.143","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-70820","references":[{"url":"https://www.xda-developers.com/nas-wouldnt-give-ssh-access-hacked-into/","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"epss":0.00183,"epssPercentile":0.08142,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-15T17:12:08.162485Z"},"ingestedAt":"2026-09-14T15:23:07.469Z","slug":"CVE-2025-70820","body":"## Overview\n\nZettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":19,"depthScoreParts":{"impact":19.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}