Account Enumeration Vulnerability in D-Link Nuclias Connect Firmware
CVE-2025-34254
What is CVE-2025-34254?
D-Link's Nuclias Connect firmware versions up to 1.3.1.4 are susceptible to an observable response discrepancy vulnerability. This flaw manifests at the application's 'Login' endpoint, where it reveals differing JSON responses based on the validity of the username input. An unauthenticated remote attacker can exploit this behavior to enumerate valid usernames on the server by analyzing variations in the error.message string. D-Link has acknowledged the issue and is actively working on a fix to address this security concern.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Nuclias Connect * < 1.3.1.4
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved