PT-2025-53647 · Zspace · Zspace Z4Pro+

Lx-66-Lx

·

Published

2025-12-28

·

Updated

2025-12-28

·

CVE-2025-15132

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZSPACE Z4Pro+ version 1.0.0440024
Description A flaw exists in ZSPACE Z4Pro+ that allows for command injection. The issue is located within the zfilev2 api open function, accessible through the /v2/file/safe/open endpoint of the HTTP POST Request Handler component. This manipulation can be initiated remotely, and details of the exploit have been publicly disclosed.
Recommendations Apply updates to address the issue in the zfilev2 api open function. As a temporary workaround, consider restricting access to the /v2/file/safe/open API endpoint until a patch is available.

Exploit

Fix

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-15132

Affected Products

Zspace Z4Pro+