CVE-2025-14188High· 7.2▾ TwilightA security vulnerability has been detected in UGREEN DH2100+ up to 5.3.0.251125. This impacts the function handler_file_backup_create of the file /v1/file/backup/create of the component nas_svr. The manipulation of the argument path lead…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.7%
A security vulnerability has been detected in UGREEN DH2100+ up to 5.3.0.251125. This impacts the function handler_file_backup_create of the file /v1/file/backup/create of the component nas_svr. The manipulation of the argument path leads to command injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading the affected component is advised.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-9582Medium· 6.3A flaw has been found in Comfast CF-N1 2.6.0
CVE-2025-9581Medium· 6.3A vulnerability was detected in Comfast CF-N1 2.6.0
CVE-2025-14108High· 8.8A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050
CVE-2025-14106High· 8.8A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050
CVE-2025-14107High· 8.8A security flaw has been discovered in ZSPACE Q2C NAS up to 1.1.0210050
CVE-2025-15391Medium· 6.3A weakness has been identified in D-Link DIR-806A 100CNb11