PT-2025-38241 · Casaos+1 · Casaos+1

0Xvpr

·

Published

2025-09-17

·

Updated

2025-09-18

·

CVE-2025-58432

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZimaOS versions prior to 1.4.1
Description ZimaOS, a fork of CasaOS, is susceptible to a file upload issue. The /v2 1/files/file/uploadV2 API endpoint permits file uploads from any user with localhost access, and these uploads are executed with root privileges.
Recommendations Update ZimaOS to version 1.4.1 or later.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2026-00215
CVE-2025-58432
GHSA-3GP9-43RG-XRCC

Affected Products

Casaos
Zimaos