CVE-2025-32002 is a critical OS Command Injection vulnerability affecting I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier, specifically when the 'Remote Link3 function' is enabled. This flaw allows a remote, unauthenticated attacker to execute arbitrary operating system commands, posing a severe risk to confidentiality, integrity, and availability. With a CVSS score of 9.8 (CRITICAL), it requires no user interaction or prior privileges for exploitation. Currently, there is no public exploit code available, nor any evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| I-O DATA DEVICE, INC. | HDL-T1NV | Ver.1.21 and earlierCNA affected | |
| I-O DATA DEVICE, INC. | HDL-T1WH | Ver.1.21 and earlierCNA affected | |
| I-O DATA DEVICE, INC. | HDL-T2NV | Ver.1.21 and earlierCNA affected | |
| I-O DATA DEVICE, INC. | HDL-T2WH | Ver.1.21 and earlierCNA affected | |
| I-O DATA DEVICE, INC. | HDL-T3NV | Ver.1.21 and earlierCNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.