Published:2025/01/14 Last Updated:2025/01/14
JVNVU#99653331
Multiple vulnerabilities in STEALTHONE D220/D340/D440
Overview
STEALTHONE D220/D340/D440 provided by Y'S corporation contain multiple vulnerabilities.
Products Affected
CVE-2025-20016
- STEALTHONE D220 firmware v6.03.02 and earlier
- STEALTHONE D340 firmware v6.03.02 and earlier
- STEALTHONE D440 firmware v7.00.10 and earlier
- STEALTHONE D220 firmware v6.03.02 and earlier
- STEALTHONE D340 firmware v6.03.02 and earlier
Description
Network storage servers STEALTHONE D220/D340/D440 provided by Y'S corporation contain multiple vulnerabilities listed below.
- OS Command Injection (CWE-78)
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Base Score 7.2
- CVE-2025-20016
- OS Command Injection (CWE-78)
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score 9.8
- CVE-2025-20055
- SQL Injection (CWE-89)
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Base Score 7.5
- CVE-2025-20620
Impact
- A user with an administrative privilege who logged in to the web management page of the affected product may execute an arbitrary OS command (CVE-2025-20016)
- An attacker who can access the affected product may execute an arbitrary OS command (CVE-2025-20055)
- An attacker who can access the affected product may obtain the administrative password of the web management page (CVE-2025-20620)
Solution
Update the firmware
Update the firmware to the latest version according to the information provided by the developer.
Vendor Status
Vendor | Link |
Y'S corporatio | D220/D340/D440 Firmware downloads and release notes (Text in Japanese) |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Chuya Hayakawa and Ryo Kamino of 00One, Inc. reported these vulnerabilities to JPCERT/CC.
JPCERT/CC coordinated with the developer.
Other Information
JPCERT Alert |
|
JPCERT Reports |
|
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2025-20016 |
CVE-2025-20055 |
|
CVE-2025-20620 |
|
JVN iPedia |
|