CVE-2025-15083
A vulnerability was determined in TOZED ZLT M30s up to 1.47.
Does this matter?
Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was determined in TOZED ZLT M30s up to 1.47. The affected element is an unknown function of the component UART Interface. Executing manipulation can lead to on-chip debug and test interface with improper access control. The physical device can be targeted for the attack. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
- CVSS 4.0
- 0.3 LOWCVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.26% probability · 18th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1191
- Affected
- gztozed/zlt m30s firmware
- Source
- cna@vuldb.com
References
- https://hacklab.eu.org/blogs/zlt_m30s_debug_interfaceExploit, Third Party Advisory
- https://vuldb.com/?ctiid.338411Permissions Required, VDB Entry
- https://vuldb.com/?id.338411Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.707974Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.