Incorrect Symlink Follow Vulnerability in Yottamaster NAS Devices
CVE-2025-69430
6.1MEDIUM
What is CVE-2025-69430?
A vulnerability in multiple Yottamaster NAS devices allows attackers to exploit an incorrect symlink follow mechanism. This security flaw can lead to unauthorized access to the device's internal file system. By formatting a USB drive as ext4, creating a symbolic link to the drive's root directory, and inserting it into a NAS device, attackers can access the symlink directory on the NAS. This allows them not only to obtain all files stored within the NAS system but also to tamper with them, posing serious risks to data integrity and confidentiality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
