CVE-2025-20016: Y's Corporation Stealthone d220

High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.

OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340/D440 provided by Y'S corporation. A user with an administrative privilege who logged in to the web management page of the affected product may execute an arbitrary OS command.

Affected products

Published 2025-01-14. Last modified 2026-06-17.