PT-2025-53406 · Tozed · Tozed Zlt M30S

S33K3R

·

Published

2025-12-25

·

Updated

2026-01-20

·

CVE-2025-15083

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TOZED ZLT M30s versions up to 1.47
Description A flaw exists in TOZED ZLT M30s up to version 1.47 related to the UART Interface component. Manipulation of an unknown function within this component can lead to improper access control to the on-chip debug and test interface. The physical device is targetable for this attack, which is described as highly complex and difficult to exploit. The exploit has been publicly disclosed, and the vendor was notified but did not respond.
Recommendations Versions up to 1.47 should be updated when a fix becomes available. As a temporary workaround, consider disabling the UART Interface component to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-15083

Affected Products

Tozed Zlt M30S