Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Absolute Path Traversal in Zettlab D6 Ultra Enables Unauthorized Access to Non-Personal Directories

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Absolute Path Traversal in Zettlab D6 Ultra Grants Unauthorized Folder Access

Mon, 14 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Title Absolute Path Traversal in Zettlab D6 Ultra Grants Unauthorized Folder Access

Sun, 13 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.
Weaknesses CWE-36
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-15T17:12:30.946Z

Reserved: 2026-01-09T00:00:00.000Z

Link: CVE-2025-70820

cve-icon Vulnrichment

Updated: 2026-09-15T17:12:14.206Z

cve-icon NVD

Status : Received

Published: 2026-09-13T20:16:50.727

Modified: 2026-09-15T18:17:12.143

Link: CVE-2025-70820

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:45:17Z

Weaknesses