Skip to main content
Vulnerability Database/CVE-2025-70819

CVE-2025-70819: Zettlab D6 Ultra Path Traversal Vulnerability

CVE-2025-70819 is a path traversal vulnerability in Zettlab D6 Ultra that allows attackers to mount sensitive system files like /etc/passwd and /etc/shadow in containers. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2025-70819 Overview

CVE-2025-70819 affects Zettlab D6 Ultra network-attached storage (NAS) devices running firmware versions before 1.7.0. The vulnerability allows a local authenticated user to mount sensitive host files, including /etc/passwd and /etc/shadow, inside a container by using .. path traversal sequences in a Docker Compose file. The flaw is classified under [CWE-24] (Path Traversal: ../filedir). An attacker who can deploy compose files on the device can escape the intended container filesystem boundary and access host-level credential material.

Critical Impact

Local attackers can read and modify host filesystem contents, including password and shadow files, leading to credential theft and potential privilege escalation on the NAS.

Affected Products

  • Zettlab D6 Ultra NAS devices
  • Firmware versions prior to 1.7.0
  • Container orchestration subsystem accepting Docker Compose input

Discovery Timeline

  • 2026-09-13 - CVE-2025-70819 published to the National Vulnerability Database
  • 2026-09-14 - Last updated in NVD database

Technical Details for CVE-2025-70819

Vulnerability Analysis

The Zettlab D6 Ultra container management interface fails to validate volume mount paths supplied through Docker Compose files. An attacker crafts a volumes: entry containing sequential parent-directory traversal segments to reference arbitrary host paths. The example payload volumes: - ../../../../../../../etc:/h_etc:rw mounts the host /etc directory into the container with read-write permissions. Once mounted, the attacker reads /etc/shadow to extract password hashes for offline cracking or modifies /etc/passwd to establish persistent access.

Root Cause

The root cause is missing canonicalization and validation of relative path segments in the compose file parser. The container runtime accepts host paths without confining them to an allowlist of permitted directories. This defect maps to [CWE-24], where .. sequences are not stripped or rejected before being passed to the mount syscall.

Attack Vector

Exploitation requires local access and low privileges on the device, consistent with the CVSS vector indicating a local attack path. The attacker must have permission to submit or edit Docker Compose configurations through the NAS management interface. After deploying a malicious compose file, the container starts with the traversed host directory bind-mounted inside. The attacker then reads or writes host files directly from within the container context, bypassing the isolation the container was expected to provide. Further technical background is described in the XDA Developers Security Analysis.

Detection Methods for CVE-2025-70819

Indicators of Compromise

  • Docker Compose files on the NAS containing .. sequences in volumes: declarations
  • Container bind mounts referencing host directories outside the standard application data paths, such as /etc, /root, or /var
  • Recently modified /etc/passwd or /etc/shadow timestamps without a corresponding administrative action
  • Unexpected user accounts or SSH authorized keys added to the host filesystem

Detection Strategies

  • Scan stored compose files and container configurations for relative path traversal patterns in mount definitions
  • Enumerate running containers on the NAS and inspect their mount tables for host paths outside expected boundaries
  • Compare current firmware version against 1.7.0 and flag devices running older builds

Monitoring Recommendations

  • Monitor filesystem integrity for /etc/passwd, /etc/shadow, and SSH key files on the NAS host
  • Log all container creation and mount operations, alerting on host paths that resolve outside the container data root
  • Track authentication events on the NAS administrative interface for accounts able to submit compose files

How to Mitigate CVE-2025-70819

Immediate Actions Required

  • Upgrade Zettlab D6 Ultra firmware to version 1.7.0 or later
  • Audit all existing Docker Compose files on the device for traversal sequences in volumes: entries and remove malicious configurations
  • Rotate credentials for any local accounts on the NAS, assuming /etc/shadow may have been exposed
  • Restrict administrative access to the container management interface to trusted operators only

Patch Information

Zettlab addresses the vulnerability in D6 Ultra firmware version 1.7.0. Administrators should apply the vendor update through the standard firmware upgrade process. Refer to the XDA Developers Security Analysis for background on the issue.

Workarounds

  • Disable the container subsystem on the NAS until the firmware update is applied
  • Enforce a manual review process for any Docker Compose file before deployment, rejecting entries containing .. in volume paths
  • Limit which local users may create or modify container workloads on the device
bash
# Configuration example: reject compose files containing parent-directory traversal in volumes
grep -RIn --include='docker-compose*.y*ml' -E 'volumes:.*\.\./' /path/to/compose/dir \
  && echo 'Traversal detected - block deployment' && exit 1

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.