Description
D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due to improper sanitization of the deleteBackupList parameter. This can allow an authenticated attacker to delete arbitrary files impacting the integrity and availability of the system.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
* before 1.3.1.4
Credits
Alex Williams from Pellera Technologies
References
www.vulncheck.com/...ry-traversal-to-arbitrary-file-deletion
www.dlink.com/en/for-business/nuclias/nuclias-connect