CVE-2025-34253
D-Link Nuclias Connect <= v1.3.1.4 Stored Cross-Site Scripting (XSS)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the 'Network' field when editing the configuration, creating a profile, and adding a network. An authenticated attacker can inject arbitrary JavaScript to be executed in the context of other users viewing the profile entry. NOTE: D-Link states that a fix is under development.
| CWE | CWE-79 |
| Vendor | d-link |
| Product | nuclias connect |
| Published | Oct 16, 2025 |
| Last Updated | May 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for d-link nuclias connect
Be the first to know when new unknown vulnerabilities affecting d-link nuclias connect are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
D-Link / Nuclias Connect
0 < 1.3.1.4
References
Credits
Alex Williams from Pellera Technologies