CVE-2025-41365: Code injection vulnerability in IDF and ZLF
Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to store malicious payload in software that will run in the victim's browser. Exploiting this vulnerability requires authenticating to the device and executing certain commands that can be executed only with permissions higher than the view permission.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41365?
CVE-2025-41365 has a high severity rating due to the potential for code injection and subsequent execution of malicious payloads in the victim's browser.
How do I fix CVE-2025-41365?
To fix CVE-2025-41365, update to the latest version of IDF and ZLF that resolves this vulnerability.
What products are affected by CVE-2025-41365?
CVE-2025-41365 affects IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04.
What type of vulnerability is CVE-2025-41365?
CVE-2025-41365 is classified as a code injection vulnerability.
Can CVE-2025-41365 be exploited remotely?
Exploiting CVE-2025-41365 requires authentication to the device, which may limit remote exploitation.