CVE Database
/

CVE-2025-34253

Back to search

CVE-2025-34253

Published: Oct 16, 2025

Modified: May 14, 2026

PUBLISHED

Description

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the 'Network' field when editing the configuration, creating a profile, and adding a network. An authenticated attacker can inject arbitrary JavaScript to be executed in the context of other users viewing the profile entry. NOTE: D-Link states that a fix is under development.

VendorProductVersions

D-Link

Nuclias Connect

affected
0 - < 1.3.1.4

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now