CVE-2025-70820
Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.
Scoring
- Severity
- LOW
- CVSS base score
- 3.5
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.18%
- CWE
- CWE-36
- Published
- 2026-09-13
- Last modified
- 2026-09-15
Affected products
- Zettlab D6 Ultra
Weakness type
Related vulnerabilities
- CVE-2024-48248 — NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /
- CVE-2024-13161 — Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
- CVE-2024-13160 — Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
- CVE-2024-13159 — Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
- CVE-2018-20250 — In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
- CVE-2023-3765 — Absolute Path Traversal in mlflow/mlflow
- CVE-2025-57790 — Path Traversal Vulnerability
- CVE-2021-21586 — Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability. A remote authenticated