CVE-2025-15133 | ZSPACE Z4Pro+ 1.0.0440024 HTTP POST Request /v2/file/safe/close zfilev2_api_CloseSafe command injection (EUVD-2025-205507)
A vulnerability was found in ZSPACE Z4Pro+ 1.0.0440024 and classified as critical. The impacted element is the function zfilev2_api_CloseSafe of the file /v2/file/safe/close of the component HTTP POST Request Handler. Such manipulation leads to command injection.
This vulnerability is referenced as CVE-2025-15133. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure.