Impact
Zettlab D6 Ultra before version 1.7.0 contains an absolute path traversal flaw that permits an attacker to reach directories outside the user’s personal folder. The flaw allows the exploitation of the device’s path handling logic, enabling unauthorized disclosure of sensitive content stored in shared or system directories, potentially compromising confidentiality. This weakness is classified as CWE‑36.
Affected Systems
The vulnerable product is Zettlab D6 Ultra, any build prior to the 1.7.0 release. No other vendors or product versions are affected according to the CNA data.
Risk and Exploitability
The CVSS base score is 3.5, indicating low severity overall. The EPSS score is less than 1%, indicating a very is not listed in CISA’s KEV catalog. Exploitation requires the ability to supply or influence path strings to the device’s file handling module. The attack vector is not explicitly documented, but it is inferred that an attacker with local or network-level access could craft malicious requests to trigger the traversal. As a result, the exploitability risk remains modest, yet the potential for accidental information disclosure warrants prompt attention.
OpenCVE Enrichment