TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2025-69429

MEDIUM
6.1

Beschreibung

The ORICO NAS CD3510 (version V1.9.12 and below) contains an Incorrect Symlink Follow vulnerability that could be exploited by attackers to leak or tamper with the internal file system. Attackers can format a USB drive to ext4, create a symbolic link to its root directory, insert the drive into the NAS device's slot, then access the USB drive's symlink directory mounted on the NAS to obtain all files within the NAS system and tamper with those files.

CVE Details

CVSS v3.1 Bewertung6.1
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
AngriffsvektorPHYSICAL
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht2/3/2026
Zuletzt geandert2/11/2026
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

orico:cd3510orico:cd3510_firmware

Schwachen (CWE)

CWE-59

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.