PT-2026-22627 · Casaos+1 · Casaos+1
Published
2026-03-02
·
Updated
2026-03-06
·
CVE-2025-64427
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
ZimaOS versions prior to 1.5.1
Description
ZimaOS, a fork of CasaOS, is susceptible to a flaw stemming from inadequate validation or restriction of target URLs. An authenticated local user can construct requests that target internal IP addresses, such as 127.0.0.1, localhost, or private network ranges. This enables interaction with internal HTTP/HTTPS services not intended for external or local user access.
Recommendations
Update ZimaOS to version 1.5.1 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Casaos
Zimaos