D-Link Nuclias Connect firmware versions <= 1.3.1.4...
Moderate severity
Unreviewed
Published
Oct 16, 2025
to the GitHub Advisory Database
•
Updated Oct 16, 2025
Description
Published by the National Vulnerability Database
Oct 16, 2025
Published to the GitHub Advisory Database
Oct 16, 2025
Last updated
Oct 16, 2025
D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Forgot Password' endpoint returns distinct JSON responses depending on whether the supplied email address is associated with an existing account. Because the responses differ in the
data.exist
boolean value, an unauthenticated remote attacker can enumerate valid email addresses/accounts on the server. NOTE: D-Link states that a fix is under development.References