CVE-2025-41363 Information

Description

In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04 a configuration error has been detected in cross-origin resource sharing (CORS). Exploiting this vulnerability requires authenticating to the device and executing certain commands that can be executed with view permission.

Reference

https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-zivs-idf-and-zlf-products

Share on: