PT-2025-53406 · Tozed · Tozed Zlt M30S
S33K3R
·
Published
2025-12-25
·
Updated
2026-01-20
·
CVE-2025-15083
CVSS v3.1
4.6
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TOZED ZLT M30s versions up to 1.47
Description
A flaw exists in TOZED ZLT M30s up to version 1.47 related to the UART Interface component. Manipulation of an unknown
function within this component can lead to improper access control to the on-chip debug and test interface. The physical device is targetable for this attack, which is described as highly complex and difficult to exploit. The exploit has been publicly disclosed, and the vendor was notified but did not respond.Recommendations
Versions up to 1.47 should be updated when a fix becomes available. As a temporary workaround, consider disabling the UART Interface component to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tozed Zlt M30S