CVE-2025-14224

A vulnerability was found in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this issue is some unknown functionality of the component File Upload. Performing manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://vuldb.com/?ctiid.334666 Permissions Required VDB Entry
https://vuldb.com/?id.334666 Third Party Advisory VDB Entry
https://vuldb.com/?submit.701673 Third Party Advisory VDB Entry
https://www.notion.so/2b76cf4e528a80f6ae50fe21b13ff0b8 Exploit Third Party Advisory
https://www.notion.so/Yottamaster-NAS-Unauth-Operation-2b76cf4e528a80f6ae50fe21b13ff0b8 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:yottamaster:dm2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:yottamaster:dm2:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:yottamaster:dm3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:yottamaster:dm3:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:yottamaster:dm200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:yottamaster:dm200:-:*:*:*:*:*:*:*

History

12 Dec 2025, 12:34

Type Values Removed Values Added
References () https://vuldb.com/?ctiid.334666 - () https://vuldb.com/?ctiid.334666 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.334666 - () https://vuldb.com/?id.334666 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.701673 - () https://vuldb.com/?submit.701673 - Third Party Advisory, VDB Entry
References () https://www.notion.so/2b76cf4e528a80f6ae50fe21b13ff0b8 - () https://www.notion.so/2b76cf4e528a80f6ae50fe21b13ff0b8 - Exploit, Third Party Advisory
References () https://www.notion.so/Yottamaster-NAS-Unauth-Operation-2b76cf4e528a80f6ae50fe21b13ff0b8 - () https://www.notion.so/Yottamaster-NAS-Unauth-Operation-2b76cf4e528a80f6ae50fe21b13ff0b8 - Exploit, Third Party Advisory
CPE cpe:2.3:h:yottamaster:dm3:-:*:*:*:*:*:*:*
cpe:2.3:o:yottamaster:dm3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:yottamaster:dm2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:yottamaster:dm200:-:*:*:*:*:*:*:*
cpe:2.3:o:yottamaster:dm200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:yottamaster:dm2:-:*:*:*:*:*:*:*
First Time Yottamaster dm200 Firmware
Yottamaster dm3
Yottamaster
Yottamaster dm2
Yottamaster dm200
Yottamaster dm3 Firmware
Yottamaster dm2 Firmware

08 Dec 2025, 14:16

Type Values Removed Values Added
References
  • () https://www.notion.so/Yottamaster-NAS-Unauth-Operation-2b76cf4e528a80f6ae50fe21b13ff0b8 -

08 Dec 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-08 09:15

Updated : 2025-12-12 12:34


NVD link : CVE-2025-14224

Mitre link : CVE-2025-14224

CVE.ORG link : CVE-2025-14224


JSON object : View

Products Affected

yottamaster

  • dm3_firmware
  • dm3
  • dm200_firmware
  • dm2_firmware
  • dm2
  • dm200
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')