CVE-2025-34254Medium· 5.3▾ SunlitD-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Login' endpoint returns distinct JSON responses depending on whether the supplied username is associated wit…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.0%
D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Login' endpoint returns distinct JSON responses depending on whether the supplied username is associated with an existing account. Because the responses differ in the error.messagestring value, an unauthenticated remote attacker can enumerate valid usernames/accounts on the server. NOTE: D-Link states that a fix is under development.
nuclias_connect <= 1.3.1.4Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-34255Medium· 5.3D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Forgot Password' endpoint returns distinct JSON responses depending on whether the supplied email address is…
CVE-2025-34253Medium· 5.4D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the 'Network' field when editing the configuration, creating a profile, and adding a network
CVE-2025-11339High· 8.8A vulnerability has been found in D-Link DI-7100G C1 up to 20250928
CVE-2025-11338High· 8.8A flaw has been found in D-Link DI-7100G C1 up to 20250928
CVE-2025-11335Medium· 4.7A weakness has been identified in D-Link DI-7100G C1 up to 20250928
CVE-2025-11100Medium· 6.3A vulnerability was identified in D-Link DIR-823X 250416