CVE-2025-32002
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.3epss 1.7%
exploitation probability
1.7%top 25% of all CVEs
observed exploitation
nono source reports it
In short
A security flaw in I-O DATA network hard drives (HDL-T Series, firmware v1.21 and earlier) allows anyone on the internet to run harmful commands on the device when Remote Link3 is enabled. This could let attackers take control of your data storage.
Technical detail
OS command injection vulnerability in I-O DATA HDL-T Series firmware affecting Remote Link3 function. An unauthenticated remote attacker can inject arbitrary OS commands through improper input sanitization. Exploitation requires Remote Link3 to be enabled, leading to complete system compromise and potential data exfiltration or destruction.
Summary generated and translated by AI from the official description.
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier when 'Remote Link3 function' is enabled. If exploited, a remote unauthenticated attacker may execute an arbitrary OS command.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N