CVE-2025-15132
ZSPACE Z4Pro+ HTTP POST Request open zfilev2_api_open command injection
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.3EPSS 6.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
28 Dec 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability was determined in ZSPACE Z4Pro+ 1.0.0440024. The affected element is the function zfilev2_api_open of the file /v2/file/safe/open of the component HTTP POST Request Handler. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
ZSPACE · Z4Pro+Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →