CVE-2025-34248: D-Link Nuclias Connect

High severity, CVSS 7.2. EPSS: 0.7% chance of exploitation in the next 30 days.

D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due to improper sanitization of the deleteBackupList parameter. This can allow an authenticated attacker to delete arbitrary files impacting the integrity and availability of the system.

Affected products

  • D-Link Nuclias Connect: before 1.3.1.4 (fixed in 1.3.1.4)

Published 2025-10-09. Last modified 2026-10-08.