Published:2025/01/14  Last Updated:2025/01/14

JVNVU#99653331
Multiple vulnerabilities in STEALTHONE D220/D340/D440

Overview

STEALTHONE D220/D340/D440 provided by Y'S corporation contain multiple vulnerabilities.

Products Affected

CVE-2025-20016

  • STEALTHONE D220 firmware v6.03.02 and earlier
  • STEALTHONE D340 firmware v6.03.02 and earlier
  • STEALTHONE D440 firmware v7.00.10 and earlier
CVE-2025-20055, CVE-2025-20620
  • STEALTHONE D220 firmware v6.03.02 and earlier
  • STEALTHONE D340 firmware v6.03.02 and earlier

Description

Network storage servers STEALTHONE D220/D340/D440 provided by Y'S corporation contain multiple vulnerabilities listed below.

  • OS Command Injection (CWE-78)
    • CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Base Score 7.2
    • CVE-2025-20016
  • OS Command Injection (CWE-78)
    • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score 9.8
    • CVE-2025-20055
  • SQL Injection (CWE-89)
    • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Base Score 7.5
    • CVE-2025-20620

Impact

  • A user with an administrative privilege who logged in to the web management page of the affected product may execute an arbitrary OS command (CVE-2025-20016)
  • An attacker who can access the affected product may execute an arbitrary OS command (CVE-2025-20055)
  • An attacker who can access the affected product may obtain the administrative password of the web management page (CVE-2025-20620)

Solution

Update the firmware
Update the firmware to the latest version according to the information provided by the developer.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Chuya Hayakawa and Ryo Kamino of 00One, Inc. reported these vulnerabilities to JPCERT/CC.
JPCERT/CC coordinated with the developer.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2025-20016
CVE-2025-20055
CVE-2025-20620
JVN iPedia