Ad

CVE-2025-64427

HIGH CVSS 3.1: 7.1 EPSS 0.04%
Updated Mar 02, 2026
Zimaos
Parameter Value
CVSS 7.1 (HIGH)
Type CWE-200 (Information Exposure), CWE-918 (Server-Side Request Forgery (SSRF))
Vendor Zimaos
Public PoC No

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prior, due to insufficient validation or restriction of target URLs, an authenticated local user can craft requests that target internal IP addresses (e.g., 127.0.0.1, localhost, or private network ranges). This allows the attacker to interact with internal HTTP/HTTPS services that are not intended to be exposed externally or to local users.

No known patch is publicly available.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
Low
Partial disruption

CVSS Vector v3.1