CVE-2025-20016: Y's Corporation Stealthone d220
High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.
OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340/D440 provided by Y'S corporation. A user with an administrative privilege who logged in to the web management page of the affected product may execute an arbitrary OS command.
Affected products
- Y's Corporation Stealthone d220: up to and including v6.03.02
- Y's Corporation Stealthone d340: up to and including v6.03.02
- Y's Corporation Stealthone d440: up to and including v7.00.10
Published 2025-01-14. Last modified 2026-06-17.