Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-34255


D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Forgot Password' endpoint returns distinct JSON responses depending on whether the supplied email address is associated with an existing account. Because the responses differ in the `data.exist` boolean value, an unauthenticated remote attacker can enumerate valid email addresses/accounts on the server. NOTE: D-Link states that a fix is under development.


Published

2025-10-16T19:15:32.920

Last Modified

2025-10-30T16:06:51.820

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-204

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dlink nuclias_connect ≤ 1.3.1.4 Yes

References