Account Enumeration Vulnerability in D-Link Nuclias Connect Firmware
CVE-2025-34255
What is CVE-2025-34255?
D-Link Nuclias Connect firmware versions up to 1.3.1.4 are susceptible to an observable response discrepancy within the 'Forgot Password' functionality. This vulnerability allows an unauthenticated attacker to determine valid email addresses associated with user accounts based on whether the supplied email address generates a distinct JSON response. The differing data.exist boolean values in the responses could potentially expose private account information. D-Link is aware of this issue and is currently developing a fix to address the vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Nuclias Connect * < 1.3.1.4
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved