Description
A vulnerability has been found in Ugreen DH2100+ up to 5.3.0. This affects an unknown function of the component USB Handler. Such manipulation leads to symlink following. The attack can be executed directly on the physical device. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Problem types
Product status
5.1
5.2
5.3.0
Timeline
| 2025-12-14: | Advisory disclosed |
| 2025-12-14: | VulDB entry created |
| 2025-12-14: | VulDB entry last update |
Credits
rgyue (VulDB User)
References
vuldb.com/?id.336411 (VDB-336411 | Ugreen DH2100+ USB symlink)
vuldb.com/?ctiid.336411 (VDB-336411 | CTI Indicators (IOB, IOC))
vuldb.com/?submit.704646 (Submit #704646 | Ugreen NAS DH2100+ V5.3.0 Incorrect Access Control)
vuldb.com/?submit.704657 (Submit #704657 | Ugreen Ugreen NAS DH2100+ V5.3.0 Incorrect Access Control (Duplicate))
www.notion.so/2bc6cf4e528a8083bf3fc6f7a953f0a1
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.