CVE-2025-61865 describes a vulnerability in multiple I-O DATA DEVICE, INC. NAS management applications, where Windows services are registered with unquoted file paths. This allows a high-privileged local attacker with write access to the system drive's root directory to execute arbitrary code with SYSTEM privileges. While the CVSS score is 6.7 (MEDIUM) due to the high impact on confidentiality, integrity, and availability, and low attack complexity, there is currently no public exploit code, Metasploit modules, or Nuclei templates available. Community discussion and media coverage for this CVE are also minimal, indicating low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| I-O DATA DEVICE, INC. | Clone For Windows | prior to Ver2.36CNA affected | |
| I-O DATA DEVICE, INC. | NarSuS App | prior to Ver.2.33CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.