CVE-2025-61871Medium· 6.7▾ SunlitNAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 36.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-12247High· 7.0A weakness has been identified in Hasleo Backup Suite up to 5.2
CVE-2025-12507High· 8.8The service Bizerba Communication Server (BCS) has an unquoted service path
CVE-2025-66461Medium· 6.7FULLBACK Manager Pro provided by GS Yuasa International Ltd
CVE-2019-25261High· 7.8AnyDesk 5.4.0 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially inject malicious executables
CVE-2020-37020High· 7.8SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by exploiting the service executable path
CVE-2021-47787High· 7.8TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem privileges