A vulnerability was determined in ZSPACE Z4Pro+ 1.0.0440024. The affected element is the function zfilev2_api_open of the file /v2/file/safe/open of the component HTTP POST Request Handler. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
Metrics
Affected Vendors & Products
References
History
Sun, 28 Dec 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in ZSPACE Z4Pro+ 1.0.0440024. The affected element is the function zfilev2_api_open of the file /v2/file/safe/open of the component HTTP POST Request Handler. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure. | |
| Title | ZSPACE Z4Pro+ HTTP POST Request open zfilev2_api_open command injection | |
| Weaknesses | CWE-74 CWE-77 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-12-28T10:32:05.208Z
Reserved: 2025-12-27T09:36:47.274Z
Link: CVE-2025-15132
No data.
Status : Received
Published: 2025-12-28T11:15:40.063
Modified: 2025-12-28T11:15:40.063
Link: CVE-2025-15132
No data.
OpenCVE Enrichment
No data.