ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and all prior versions, the /v2_1/files/file/uploadV2 endpoint allows file upload from ANY USER who has access to localhost. File uploads are performed AS ROOT.
History

Thu, 18 Sep 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Icewhaletech
Icewhaletech zimaos
Zimaspace
Zimaspace zimaos
Vendors & Products Icewhaletech
Icewhaletech zimaos
Zimaspace
Zimaspace zimaos

Wed, 17 Sep 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 17 Sep 2025 17:45:00 +0000

Type Values Removed Values Added
Description ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and all prior versions, the /v2_1/files/file/uploadV2 endpoint allows file upload from ANY USER who has access to localhost. File uploads are performed AS ROOT.
Title ZimaOS Privilege Escalation using localhost calls to File API Upload
Weaknesses CWE-250
CWE-269
References
Metrics cvssV4_0

{'score': 5.2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-09-17T17:31:20.968Z

Updated: 2025-09-17T17:47:32.620Z

Reserved: 2025-09-01T20:03:06.531Z

Link: CVE-2025-58432

cve-icon Vulnrichment

Updated: 2025-09-17T17:47:24.011Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-17T18:15:52.533

Modified: 2025-09-18T13:43:34.310

Link: CVE-2025-58432

cve-icon Redhat

No data.