Metrics
Affected Vendors & Products
Tue, 09 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ugreen
Ugreen dh2100+ |
|
| Vendors & Products |
Ugreen
Ugreen dh2100+ |
Mon, 08 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 07 Dec 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in UGREEN DH2100+ up to 5.3.0.251125. This affects the function handler_file_backup_create of the file /v1/file/backup/create of the component nas_svr. Executing manipulation of the argument path can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | UGREEN DH2100+ nas_svr create handler_file_backup_create buffer overflow | |
| Weaknesses | CWE-119 CWE-120 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-12-08T17:12:42.141Z
Reserved: 2025-12-06T14:14:50.530Z
Link: CVE-2025-14187
Updated: 2025-12-08T17:03:13.163Z
Status : Awaiting Analysis
Published: 2025-12-07T09:15:48.307
Modified: 2025-12-08T18:26:49.133
Link: CVE-2025-14187
No data.