Vulnerability Details CVE-2025-34253
D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the 'Network' field when editing the configuration, creating a profile, and adding a network. An authenticated attacker can inject arbitrary JavaScript to be executed in the context of other users viewing the profile entry. NOTE: D-Link states that a fix is under development.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 4.2%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2025-34253
-
cpe:2.3:a:dlink:nuclias_connect:1.3.1.2
-
cpe:2.3:a:dlink:nuclias_connect:1.3.1.4