CVE-2025-70231: Path Traversal
D-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST requests related to verification codes in /goform/formLogin, it enters /goform/getAuthCode but fails to filter the value of the FILECODE parameter, resulting in a path traversal vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70231?
CVE-2025-70231 is classified as a critical-level vulnerability due to its potential impact on the system's security.
How do I fix CVE-2025-70231?
To fix CVE-2025-70231, you should update the D-Link DIR-513 firmware to a version that addresses this vulnerability.
What type of attack is CVE-2025-70231 associated with?
CVE-2025-70231 is associated with path traversal attacks, which can allow unauthorized file access.
Which version of D-Link DIR-513 is affected by CVE-2025-70231?
CVE-2025-70231 affects D-Link DIR-513 version 1.10.
What component of the D-Link DIR-513 is vulnerable in CVE-2025-70231?
The vulnerability in CVE-2025-70231 is found in the processing of POST requests related to verification codes in the /goform/formLogin component.