CVE-2025-14187

HIGH

UGREEN DH2100+ <5.3.0.251125 - Buffer Overflow

Title source: llm
STIX 2.1

Description

A weakness has been identified in UGREEN DH2100+ up to 5.3.0.251125. This affects the function handler_file_backup_create of the file /v1/file/backup/create of the component nas_svr. Executing a manipulation of the argument path can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. It is recommended to upgrade the affected component.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.334607
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.334607
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.698652

Scores

CVSS v3 7.2
EPSS 0.0002
EPSS Percentile 6.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-119 CWE-120
Status published
Products (1)
UGREEN/DH2100+ 5.3.0.251125
Published Dec 07, 2025
Tracked Since Feb 18, 2026