---
id: CVE-2025-14693
title: A vulnerability has been found in Ugreen DH2100+ up to 5.3.0
summary: >-
  A vulnerability has been found in Ugreen DH2100+ up to 5.3.0. This affects an
  unknown function of the component USB Handler. Such manipulation leads to
  symlink following. The attack can be executed directly on the physical device.
  The ex…
severity: medium
cvss: 6.2
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-59
  - CWE-61
published: '2025-12-15'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14693'
references:
  - url: 'https://vuldb.com/?ctiid.336411'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.336411'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.704646'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.704657'
    label: cna@vuldb.com
  - url: 'https://www.notion.so/2bc6cf4e528a8083bf3fc6f7a953f0a1'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00219
epssPercentile: 0.11322
ingestedAt: '2026-10-07T19:44:15.674Z'
---

## Overview

A vulnerability has been found in Ugreen DH2100+ up to 5.3.0. This affects an unknown function of the component USB Handler. Such manipulation leads to symlink following. The attack can be executed directly on the physical device. The exploit has been disclosed to the public and may be used. It is suggested to upgrade the affected component.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
