CVE-2025-70820: Path Traversal
Published Sep 13, 2026
·Updated
Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.
Affected Software
1 affected component
Zettlab D6 Ultra<1.7.0
Event History
Sep 13, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attack vector is adjacent network access, and the attacker must already have low-level privileges. No user interaction is required.
2
Which systems are affected?
Zettlab D6 Ultra devices running versions before 1.7.0 are affected. The issue allows traversal to folders outside the personal folder.