CVE-2025-61865 Details
Description
Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
A vulnerability exists in the I-O DATA NarSuS App due to the registration of a Windows service with an unquoted file path. This flaw allows users with write permissions on the root directory of the system drive to execute arbitrary code with SYSTEM privileges. The vulnerability affects NarSuS App versions prior to 2.33.
Users are advised to update the NarSuS App to version 2.33 or later. The latest version can be downloaded from the I-O DATA website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 23, 2025CISA-ADP
Assessed Oct 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/jp/JVN03295012/ | [email protected] | AdvisoryRemedy |
| https://www.iodata.jp/support/information/2025/10_NarSuS_App/ | [email protected] | AdvisoryRemedyVendor |
| https://www.iodata.jp/support/information/2025/12_CloneforWindows/ | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-428 | Unquoted Search Path or Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| I-O DATA NarSuS App | All versions |
CPE
Remediation
| |
| I-O DATA LAN DISK Z | All versions |
CPE
Remediation
| |
| I-O DATA HDLM3-GWIN | All versions |
CPE
Remediation
| |
| I-O DATA APX | All versions |
CPE
Remediation
| |
| I-O DATA APX2 | All versions |
CPE
Remediation
| |
| I-O DATA APS2 | All versions |
CPE
Remediation
| |
| I-O DATA WE1-TS5/PACK | All versions |
CPE
Remediation
| |
| I-O DATA WE2C-SKYSEA | All versions |
CPE
Remediation
| |
| I-O DATA WE2C-VISUACTL | All versions |
CPE
Remediation
| |
| I-O DATA WEC-RSIO3Y | All versions |
CPE
Remediation
| |
| I-O DATA WEC-VISUACTL | All versions |
CPE
Remediation
| |
| I-O DATA HDL-Z2WH2T | All versions |
CPE
Remediation
| |
| I-O DATA HDL-Z2WE | All versions |
CPE
Remediation
| |
| I-O DATA HDL2-Z10ATA | All versions |
CPE
Remediation
| |
| I-O DATA ZHD-UTX | All versions |
CPE
Remediation
| |
| I-O DATA ZHD2-UTX | All versions |
CPE
Remediation
| |
| I-O DATA ZHD4-UTX | All versions |
CPE
Remediation
| |
| I-O DATA HDJA-UT | All versions |
CPE
Remediation
| |
| I-O DATA HDJA-SUT | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 10, 2025 | CVE Modified | [email protected] |
| Oct 23, 2025 | New CVE Received | [email protected] |
Volerion