Zimaspace

Zimaos

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 13.63%
  • Veröffentlicht 08.01.2026 14:00:14
  • Zuletzt bearbeitet 12.01.2026 17:13:00

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application checks the validity of the username but appears to skip, misinterpret, or incorrectly validate the p...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 17.09.2025 17:31:20
  • Zuletzt bearbeitet 22.09.2025 14:24:42

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and all prior versions, the /v2_1/files/file/uploadV2 endpoint allows file upload from ANY USER who has access to localhost. File uploads ...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 17.09.2025 17:25:08
  • Zuletzt bearbeitet 22.09.2025 14:21:36

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and earlier, the /v2_1/files/file/download endpoint allows file read from ANY USER who has access to localhost. File reads are performed A...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 24.10.2024 22:15:04
  • Zuletzt bearbeitet 22.09.2025 14:21:56

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Server-IP>/v1/users/login` in ZimaOS returns distinct responses based on whether a usern...

Exploit
  • EPSS 0.8%
  • Veröffentlicht 24.10.2024 22:15:04
  • Zuletzt bearbeitet 22.09.2025 14:21:53

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Zima_Server_IP:PORT>/v2_1/file` in ZimaOS is vulnerable to a directory traversal attack,...

Exploit
  • EPSS 2.31%
  • Veröffentlicht 24.10.2024 22:15:03
  • Zuletzt bearbeitet 22.09.2025 14:21:51

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoints in ZimaOS, such as `http://<Server-IP>/v1/users/image?path=/var/lib/casaos/1/app_order.json` and...