First published: Thu May 15 2025(Updated: )
Missing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier. If exploited, a remote unauthenticated attacker may change the product settings.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
I-O DATA HDL-T Series | <=1.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32738 is classified as a critical vulnerability due to the potential for remote unauthenticated access to change essential product settings.
To mitigate CVE-2025-32738, users should upgrade the I-O DATA HDL-T Series firmware to version 1.22 or later.
CVE-2025-32738 affects the I-O DATA HDL-T Series network attached hard disks running firmware versions 1.21 and earlier.
If exploited, CVE-2025-32738 allows an attacker to change critical settings of the device without authentication, potentially leading to data loss or unauthorized access.
No, CVE-2025-32738 can be exploited by a remote attacker without any form of authentication.