CVE-2025-32002: I-O Data Device, Inc Hdl-t1nv
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier when 'Remote Link3 function' is enabled. If exploited, a remote unauthenticated attacker may execute an arbitrary OS command.
Affected products
- I-O Data Device, Inc Hdl-t1nv: up to and including 1.21
- I-O Data Device, Inc Hdl-t1wh: up to and including 1.21
- I-O Data Device, Inc Hdl-t2nv: up to and including 1.21
- I-O Data Device, Inc Hdl-t2wh: up to and including 1.21
- I-O Data Device, Inc Hdl-t3nv: up to and including 1.21
- I-O Data Device, Inc Hdl-t3wh: up to and including 1.21
- I-O Data Device, Inc Hdl-TC1: up to and including 1.21
- I-O Data Device, Inc Hdl-TC500: up to and including 1.21
Published 2025-05-15. Last modified 2026-06-17.