Fiche vulnérabilité
CVE-2025-58431 : faille moyenne zimaspace zimaos (CVSS 6.2)
Description
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and earlier, the /v2_1/files/file/download endpoint allows file read from ANY USER who has access to localhost. File reads are performed AS ROOT.
En bref
- Sévérité
- Moyenne (CVSS 6.2)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 17 sept. 2025
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- zimaspace zimaos