Multiple F5 BIG-IP Products Vulnerabilities
October 21, 2025Microsoft 365 Copilot Prompt Injection Flaw Enables Data Theft
October 22, 2025Multiple F5 BIG-IP Products Vulnerabilities
October 21, 2025Microsoft 365 Copilot Prompt Injection Flaw Enables Data Theft
October 22, 2025Severity
Medium
Analysis Summary
CVE-2025-34253 CVSS:5.4
D-Link Nuclias Connect is vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input by the endpoint of editing the configuration, creating a profile, and adding a network. A remote authenticated attacker could exploit this vulnerability using the Network field to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed.
CVE-2025-34255 CVSS:5.3
D-Link Nuclias Connect could allow a remote attacker to obtain sensitive information due to an observable response discrepancy vulnerability in the 'data.exist' boolean value of the 'forgot password' endpoint. A remote attacker could exploit this vulnerability to enumerate valid email addresses/accounts on the server.
CVE-2025-34254 CVSS:6.5
D-Link Nuclias Connect could allow a remote attacker to obtain sensitive information due to an observable response discrepancy vulnerability in the 'error.message' string value of the 'Login' endpoint. A remote attacker could exploit this vulnerability to enumerate valid usernames/accounts on the server.
Impact
- Information Disclosure
- Cross-site Scripting
Indicators of Compromise
CVE
CVE-2025-34253
CVE-2025-34255
CVE-2025-34254
Affected Vendors
- D-Link
Affected Products
- D-Link Nuclias Connect 1.3.1.2
- D-Link Nuclias Connect 1.3.1.4
Remediation
Refer to D-Link for patch, upgrade, or suggested workaround information.