Description
A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated user with limited privileges, by issuing a specifically-crafted request, can potentially alter the structure and content of files in the /data folder, and/or affect their availability.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Any version before 25.2.0
Any version before 25.2.0
Credits
This issue was found by Andrea Palanca of Nozomi Networks Product Security team during an internal investigation.
References
security.nozominetworks.com/NN-2025:9-01