CVE-2025-64427Disclosure(zimaspace / zimaos)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prior, due to insufficient validation or restriction of target URLs, an authenticated local user can craft requests that target internal IP addresses (e.g., 127.0.0.1, localhost, or private network ranges). This allows the attacker to interact with internal HTTP/HTTPS services that are not intended to be exposed externally or to local users. No known patch is publicly available.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zimaos

Threat summary

  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-03-02); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
zimaos

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-02: 2Mentions · 2026-03-03: 1Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Technical Details · 2026-03-02: 2Technical Details · 2026-03-03: 1Technical Details · 2026-03-06: 103-0203-0303-0503-06
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-022
Disclosure2
2026-03-031
Disclosure1
2026-03-051
General1
2026-03-061
General1
Full discourse5 posts
  • CRAC Learning - Tech@cracbot
    General

    CVE-2025-64427 (CVSS:7.1, HIGH) is Analyzed. ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prio..https://nvd.nist.gov/vuln/detail/CVE-2025-64427 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2025‑64427, provides its CVSS score, and links to NVD, but offers no evidence of exploitation, patches, or a PoC.

    0000056
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2025-64427 (CVSS:7.1, HIGH) is Undergoing Analysis. ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prio..https://nvd.nist.gov/vuln/detail/CVE-2025-64427 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces that CVE-2025-64427 is under analysis, offering only a CVSS score and an NVD link, without any PoC, exploit, patch or technical details.

    0000042
    173 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-64427 ZimaOS 1.5.0 Server-Side Request Forgery via Authenticated URL Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-64427

    Post summary

    A new SSRF vulnerability (CVE-2025-64427) in ZimaOS 1.5.0 is disclosed, involving authenticated URL manipulation.

    0000090
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-64427 ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prior, due to insufficient validation or restricti… https://www.cve.org/CVERecord?id=CVE-2025-64427 ----- Traducción: CVE-2025-64427 Zim… http://infoflow.cloud`

    Post summary

    CVE-2025-64427 is disclosed as a validation issue in ZimaOS versions 1.5.0 and earlier, with no PoC, exploit, or patch details provided.

    0000097
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-64427 ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prior, due to insufficient validation or restricti… https://www.cve.org/CVERecord?id=CVE-2025-64427

    Post summary

    CVE-2025-64427 impacts ZimaOS 1.5.0 and earlier due to insufficient validation or restrictions; no PoC, exploit, patch, or active exploitation is mentioned.

    00000242
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSzimaspacezimaos---

Explore more