CVE-2025-15133

Source
https://cve.org/CVERecord?id=CVE-2025-15133
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15133.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-15133
Published
2025-12-28T11:15:41.217Z
Modified
2026-03-15T22:51:02.289586Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability was identified in ZSPACE Z4Pro+ 1.0.0440024. The impacted element is the function zfilev2apiCloseSafe of the file /v2/file/safe/close of the component HTTP POST Request Handler. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.0.0440024"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15133.json"