A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to enumerate valid usernames and their associated privilege roles. The issue is triggered by modifying a parameter within requests sent to the /nasapi endpoint.
References
| Link | Resource |
|---|---|
| https://github.com/DBmonster19/CVE-2025-66954 |
Configurations
No configuration.
History
20 Apr 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-20 17:16
Updated : 2026-04-20 19:05
NVD link : CVE-2025-66954
Mitre link : CVE-2025-66954
CVE.ORG link : CVE-2025-66954
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
