CVE-2025-32738: I-O Data Device, Inc Hdl-t1nv
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Missing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier. If exploited, a remote unauthenticated attacker may change the product settings.
Affected products
- I-O Data Device, Inc Hdl-t1nv: up to and including 1.21
- I-O Data Device, Inc Hdl-t1wh: up to and including 1.21
- I-O Data Device, Inc Hdl-t2nv: up to and including 1.21
- I-O Data Device, Inc Hdl-t2wh: up to and including 1.21
- I-O Data Device, Inc Hdl-t3nv: up to and including 1.21
- I-O Data Device, Inc Hdl-t3wh: up to and including 1.21
- I-O Data Device, Inc Hdl-TC1: up to and including 1.21
- I-O Data Device, Inc Hdl-TC500: up to and including 1.21
Published 2025-05-15. Last modified 2026-06-17.