An Incorrect Symlink Follow vulnerability exists in multiple Yottamaster NAS devices, including DM2 (version equal to or prior to V1.9.12), DM3 (version equal to or prior to V1.9.12), and DM200 (version equal to or prior to V1.2.23) that could be exploited by attackers to leak or tamper with the internal file system. Attackers can format a USB drive to ext4, create a symbolic link to its root directory, insert the drive into the NAS device's slot, then access the USB drive's symlink directory mounted on the NAS to obtain all files within the NAS system and tamper with those files.

Project Subscriptions

Vendors Products
Yottamaster Subscribe
Dm200 Firmware Subscribe
Dm2 Firmware Subscribe
Dm3 Firmware Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 11 Feb 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Yottamaster dm200 Firmware
Yottamaster dm2 Firmware
Yottamaster dm3 Firmware
CPEs cpe:2.3:h:yottamaster:dm200:-:*:*:*:*:*:*:*
cpe:2.3:h:yottamaster:dm2:-:*:*:*:*:*:*:*
cpe:2.3:h:yottamaster:dm3:-:*:*:*:*:*:*:*
cpe:2.3:o:yottamaster:dm200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:yottamaster:dm2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:yottamaster:dm3_firmware:*:*:*:*:*:*:*:*
Vendors & Products Yottamaster dm200 Firmware
Yottamaster dm2 Firmware
Yottamaster dm3 Firmware

Fri, 06 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 05 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-59
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 04 Feb 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Yottamaster
Yottamaster dm2
Yottamaster dm200
Yottamaster dm3
Vendors & Products Yottamaster
Yottamaster dm2
Yottamaster dm200
Yottamaster dm3

Tue, 03 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
Description An Incorrect Symlink Follow vulnerability exists in multiple Yottamaster NAS devices, including DM2 (version equal to or prior to V1.9.12), DM3 (version equal to or prior to V1.9.12), and DM200 (version equal to or prior to V1.2.23) that could be exploited by attackers to leak or tamper with the internal file system. Attackers can format a USB drive to ext4, create a symbolic link to its root directory, insert the drive into the NAS device's slot, then access the USB drive's symlink directory mounted on the NAS to obtain all files within the NAS system and tamper with those files.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-02-06T20:18:51.001Z

Reserved: 2026-01-09T00:00:00.000Z

Link: CVE-2025-69430

cve-icon Vulnrichment

Updated: 2026-02-05T14:44:27.101Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-03T18:16:16.817

Modified: 2026-02-11T16:34:28.093

Link: CVE-2025-69430

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-04T12:17:16Z

Weaknesses