---
id: CVE-2025-14220
title: A security vulnerability has been detected in ORICO CD3510 1.9.12
summary: >-
  A security vulnerability has been detected in ORICO CD3510 1.9.12. This
  affects an unknown function of the component File Upload. The manipulation
  leads to path traversal. The attack can be initiated remotely. The exploit has
  been disclo…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-22
published: '2025-12-08'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14220'
references:
  - url: 'https://vuldb.com/?ctiid.334662'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.334662'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.701302'
    label: cna@vuldb.com
  - url: 'https://www.notion.so/2b66cf4e528a8002aa39df57a71b105a'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00414
epssPercentile: 0.33509
ingestedAt: '2026-10-07T20:46:46.750Z'
---

## Overview

A security vulnerability has been detected in ORICO CD3510 1.9.12. This affects an unknown function of the component File Upload. The manipulation leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
