← voltar
CVE-2025-14187

UGREEN DH2100+ nas_svr create handler_file_backup_create buffer overflow

CVSS 8.6 HIGHEPSS 0.6%CWE-119CWE-120
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 8.6EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
07 dez 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A weakness has been identified in UGREEN DH2100+ up to 5.3.0.251125. This affects the function handler_file_backup_create of the file /v1/file/backup/create of the component nas_svr. Executing a manipulation of the argument path can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. It is recommended to upgrade the affected component.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Produtos afetados
UGREEN · DH2100+

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →