CVE-2025-64427 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prior, due to insufficient validation or res…
High CVSS: 7.1

CVE-2025-64427

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prior, due to insufficient validation or restriction of target URLs, an authenticated local user can craft requests that target internal IP addresses (e.g., 127.0.0.1, localhost, or private network ranges). This allows the attacker to interact with internal HTTP/HTTPS services that are not intended to be exposed externally or to local users. No known patch is publicly available.
Vendor
Zimaspace
Product
Zimaos
CWE
CWE-200
Yayın Tarihi
2026-03-02 17:16:28
Güncelleme
2026-03-05 15:18:14
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar