---
id: CVE-2025-34254
title: "D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability.\_The application's 'Login' endpoint returns distinct JSON responses depending on whether the supplied username is associated wit…"
summary: "D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability.\_The application's 'Login' endpoint returns distinct JSON responses depending on whether the supplied username is associated wit…"
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-204
vendor: dlink
product: nuclias_connect
affected:
  - nuclias_connect <= 1.3.1.4
published: '2025-10-16'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34254'
references:
  - url: >-
      https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10472
    label: disclosure@vulncheck.com
  - url: 'https://www.dlink.com/en/for-business/nuclias/nuclias-connect'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/dlink-nuclias-connect-login-account-enumeration
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.01023
epssPercentile: 0.62392
ingestedAt: '2026-10-09T12:53:29.094Z'
---

## Overview

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Login' endpoint returns distinct JSON responses depending on whether the supplied username is associated with an existing account. Because the responses differ in the `error.message`string value, an unauthenticated remote attacker can enumerate valid usernames/accounts on the server. NOTE: D-Link states that a fix is under development.

## Affected

- `nuclias_connect <= 1.3.1.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
