CVE-2025-69431 describes an incorrect symbolic link following vulnerability in ZSPACE Q2C NAS devices, including its firmware. This flaw allows an attacker with physical access to a USB slot to create a specially crafted USB drive, tricking the NAS into mounting it and exposing its root directory via Samba. The vulnerability carries a CVSS score of 6.1 (Medium), indicating a low attack complexity and no user interaction required, but necessitates physical access to the device. Successful exploitation could lead to full compromise of NAS files, including data exfiltration and tampering. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1.0210050CPE matchmatch criteria | cpe:2.3:o:zspace:q2c_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.