CVE-2025-15082

A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post of the component Web Management Interface. Performing manipulation of the argument goformId results in information disclosure. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://vuldb.com/?ctiid.338410 Permissions Required VDB Entry
https://vuldb.com/?id.338410 Third Party Advisory VDB Entry
https://vuldb.com/?submit.707306 Third Party Advisory VDB Entry
https://www.hacklab.eu.org/blogs/zlt_m30s_information_disclosure Exploit Third Party Advisory
https://youtu.be/u_H29UdiPOc Exploit
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:gztozed:zlt_m30s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gztozed:zlt_m30s:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-25 17:15

Updated : 2026-01-20 19:54


NVD link : CVE-2025-15082

Mitre link : CVE-2025-15082

CVE.ORG link : CVE-2025-15082


JSON object : View

Products Affected

gztozed

  • zlt_m30s_firmware
  • zlt_m30s
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-284

Improper Access Control

NVD-CWE-noinfo