CVE-2025-14224

A vulnerability was found in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this issue is some unknown functionality of the component File Upload. Performing manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://vuldb.com/?ctiid.334666 Permissions Required VDB Entry
https://vuldb.com/?id.334666 Third Party Advisory VDB Entry
https://vuldb.com/?submit.701673 Third Party Advisory VDB Entry
https://www.notion.so/2b76cf4e528a80f6ae50fe21b13ff0b8 Exploit Third Party Advisory
https://www.notion.so/Yottamaster-NAS-Unauth-Operation-2b76cf4e528a80f6ae50fe21b13ff0b8 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:yottamaster:dm2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:yottamaster:dm2:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:yottamaster:dm3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:yottamaster:dm3:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:yottamaster:dm200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:yottamaster:dm200:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-08 09:15

Updated : 2025-12-12 12:34


NVD link : CVE-2025-14224

Mitre link : CVE-2025-14224

CVE.ORG link : CVE-2025-14224


JSON object : View

Products Affected

yottamaster

  • dm3_firmware
  • dm3
  • dm2_firmware
  • dm200_firmware
  • dm200
  • dm2
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')