Vulnerabilities
Vulnerable Software
Zimaspace:  >> Zimaos  >> 1.3.2  Security Vulnerabilities
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and earlier, the /v2_1/files/file/download endpoint allows file read from ANY USER who has access to localhost. File reads are performed AS ROOT.
CVSS Score
6.2
EPSS Score
0.0
Published
2025-09-17
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and all prior versions, the /v2_1/files/file/uploadV2 endpoint allows file upload from ANY USER who has access to localhost. File uploads are performed AS ROOT.
CVSS Score
7.8
EPSS Score
0.0
Published
2025-09-17


Contact Us

Shodan ® - All rights reserved