PT-2025-21217 · I O Data · I-O Data Hdl-T Series

·

CVE-2025-32002

·

Published

2025-05-14

·

Updated

2025-05-17

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: I-O DATA HDL-T Series firmware versions 1.21 and earlier
Description: The issue is related to the improper neutralization of special elements used in an OS command, also known as 'OS Command Injection'. This problem exists in the I-O DATA network attached hard disk 'HDL-T Series' firmware when the 'Remote Link3 function' is enabled. If exploited, a remote unauthenticated attacker may execute an arbitrary OS command.
Recommendations: For I-O DATA HDL-T Series firmware versions 1.21 and earlier, update the firmware to a version that contains a fix for this issue as soon as possible. As a temporary workaround, consider disabling the 'Remote Link3 function' to minimize the risk of exploitation.

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07450
CVE-2025-32002

Affected Products

I-O Data Hdl-T Series