PT-2025-53405 · Tozed · Tozed Zlt M30S

S33K3R

·

Published

2025-12-25

·

Updated

2026-01-20

·

CVE-2025-15082

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TOZED ZLT M30s versions up to 1.47
Description A flaw exists in TOZED ZLT M30s, specifically within the Web Management Interface component. Manipulation of the goformId argument in a request to the /reqproc/proc post file can lead to information disclosure. The attack can be initiated remotely. The exploit for this issue has been publicly released. The vendor was notified but did not respond.
Recommendations Versions up to 1.47 should be updated when a fix becomes available. As a temporary workaround, consider restricting access to the /reqproc/proc post file to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-15082

Affected Products

Tozed Zlt M30S