CVE-2025-61865: I-O Data Device, Inc Clone For Windows

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.

Affected products

Published 2025-10-23. Last modified 2026-06-17.