CVE-2025-70819 Overview
CVE-2025-70819 affects Zettlab D6 Ultra network-attached storage (NAS) devices running firmware versions before 1.7.0. The vulnerability allows a local authenticated user to mount sensitive host files, including /etc/passwd and /etc/shadow, inside a container by using .. path traversal sequences in a Docker Compose file. The flaw is classified under [CWE-24] (Path Traversal: ../filedir). An attacker who can deploy compose files on the device can escape the intended container filesystem boundary and access host-level credential material.
Critical Impact
Local attackers can read and modify host filesystem contents, including password and shadow files, leading to credential theft and potential privilege escalation on the NAS.
Affected Products
- Zettlab D6 Ultra NAS devices
- Firmware versions prior to 1.7.0
- Container orchestration subsystem accepting Docker Compose input
Discovery Timeline
- 2026-09-13 - CVE-2025-70819 published to the National Vulnerability Database
- 2026-09-14 - Last updated in NVD database
Technical Details for CVE-2025-70819
Vulnerability Analysis
The Zettlab D6 Ultra container management interface fails to validate volume mount paths supplied through Docker Compose files. An attacker crafts a volumes: entry containing sequential parent-directory traversal segments to reference arbitrary host paths. The example payload volumes: - ../../../../../../../etc:/h_etc:rw mounts the host /etc directory into the container with read-write permissions. Once mounted, the attacker reads /etc/shadow to extract password hashes for offline cracking or modifies /etc/passwd to establish persistent access.
Root Cause
The root cause is missing canonicalization and validation of relative path segments in the compose file parser. The container runtime accepts host paths without confining them to an allowlist of permitted directories. This defect maps to [CWE-24], where .. sequences are not stripped or rejected before being passed to the mount syscall.
Attack Vector
Exploitation requires local access and low privileges on the device, consistent with the CVSS vector indicating a local attack path. The attacker must have permission to submit or edit Docker Compose configurations through the NAS management interface. After deploying a malicious compose file, the container starts with the traversed host directory bind-mounted inside. The attacker then reads or writes host files directly from within the container context, bypassing the isolation the container was expected to provide. Further technical background is described in the XDA Developers Security Analysis.
Detection Methods for CVE-2025-70819
Indicators of Compromise
- Docker Compose files on the NAS containing .. sequences in volumes: declarations
- Container bind mounts referencing host directories outside the standard application data paths, such as /etc, /root, or /var
- Recently modified /etc/passwd or /etc/shadow timestamps without a corresponding administrative action
- Unexpected user accounts or SSH authorized keys added to the host filesystem
Detection Strategies
- Scan stored compose files and container configurations for relative path traversal patterns in mount definitions
- Enumerate running containers on the NAS and inspect their mount tables for host paths outside expected boundaries
- Compare current firmware version against 1.7.0 and flag devices running older builds
Monitoring Recommendations
- Monitor filesystem integrity for /etc/passwd, /etc/shadow, and SSH key files on the NAS host
- Log all container creation and mount operations, alerting on host paths that resolve outside the container data root
- Track authentication events on the NAS administrative interface for accounts able to submit compose files
How to Mitigate CVE-2025-70819
Immediate Actions Required
- Upgrade Zettlab D6 Ultra firmware to version 1.7.0 or later
- Audit all existing Docker Compose files on the device for traversal sequences in volumes: entries and remove malicious configurations
- Rotate credentials for any local accounts on the NAS, assuming /etc/shadow may have been exposed
- Restrict administrative access to the container management interface to trusted operators only
Patch Information
Zettlab addresses the vulnerability in D6 Ultra firmware version 1.7.0. Administrators should apply the vendor update through the standard firmware upgrade process. Refer to the XDA Developers Security Analysis for background on the issue.
Workarounds
- Disable the container subsystem on the NAS until the firmware update is applied
- Enforce a manual review process for any Docker Compose file before deployment, rejecting entries containing .. in volume paths
- Limit which local users may create or modify container workloads on the device
# Configuration example: reject compose files containing parent-directory traversal in volumes
grep -RIn --include='docker-compose*.y*ml' -E 'volumes:.*\.\./' /path/to/compose/dir \
&& echo 'Traversal detected - block deployment' && exit 1
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
