CVE-2025-15082: TOZED ZLT M30s Web Management proc_post information disclosure
A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/procpost of the component Web Management Interface. Performing manipulation of the argument goformId results in information disclosure. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15082?
CVE-2025-15082 has not been assigned a severity rating yet, but it can lead to information disclosure.
How do I fix CVE-2025-15082?
To mitigate CVE-2025-15082, update the TOZED ZLT M30s firmware to version 1.48 or later.
What type of vulnerability is CVE-2025-15082?
CVE-2025-15082 is a security vulnerability that allows for information disclosure through Web Management Interface manipulation.
Which devices are affected by CVE-2025-15082?
CVE-2025-15082 affects TOZED ZLT M30s devices running versions up to and including 1.47.
What is the attack vector for CVE-2025-15082?
The attack vector for CVE-2025-15082 involves manipulating the 'goformId' argument in the Web Management Interface.