CVE-2025-15132

HIGH WAF: High
CVSS 8.8 Published: 2025-12-28
CWE-77 CWE-77

A vulnerability was determined in ZSPACE Z4Pro+ 1.0.0440024. The affected element is the function zfilev2_api_open of the file /v2/file/safe/open of the component HTTP POST Request Handler. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.

WAF Coverage Analysis

Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution
Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
zspacez4pro\+_firmwareup to 1.0.0440024

References

  • github.com (Exploit, Third Party Advisory, Issue Tracking)
  • vuldb.com (Permissions Required, VDB Entry)
  • vuldb.com (Third Party Advisory, VDB Entry)
  • vuldb.com (Third Party Advisory, VDB Entry)
Back to CVE Database