Back to Database
Status published
Medium
CVE-2025-58431
ZimaOS reads arbitrary files using localhost calls to File API Download
Vulnerability Description
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and earlier, the /v2_1/files/file/download endpoint allows file read from ANY USER who has access to localhost. File reads are performed AS ROOT.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-58431
Credits & Attribution
No credits recorded in the NVD database.
More from IceWhaleTech
View All →CVE-2025-64427
ZimaOS is vulnerable to Server-Side Request Forgery (SSRF)
High
7.1
CVE-2025-58432
ZimaOS Privilege Escalation using localhost calls to File API Upload
Medium
5.2
CVE-2024-49359
ZimaOS vulnerable to Directory Listing via Parameter Manipulation
High
7.5
CVE-2024-49358
ZimaOS vulnerable to Username Enumeration via API Responses
Medium
5.3
CVE-2024-49357
ZimaOS (Installed Applications and System Information) has Unauthorized Sensitive Data Leak
High
7.5
Affected Vendor
IceWhaleTech
View all reports →Affected Software
ZimaOS
Vulnerable Versions:
<= 1.4.1
Timeline
Official Publish:
September 17th, 2025
Last Modified:
September 17th, 2025
Added to House:
July 22nd, 2026