CVE-2025-64427 - CVE House
Back to Database
Status published High CVE-2025-64427

ZimaOS is vulnerable to Server-Side Request Forgery (SSRF)

Vulnerability Description

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prior, due to insufficient validation or restriction of target URLs, an authenticated local user can craft requests that target internal IP addresses (e.g., 127.0.0.1, localhost, or private network ranges). This allows the attacker to interact with internal HTTP/HTTPS services that are not intended to be exposed externally or to local users. No known patch is publicly available.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-64427

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

IceWhaleTech

View all reports →

Affected Software

ZimaOS
Vulnerable Versions:
< 1.5.0

Timeline

Official Publish: March 2nd, 2026
Last Modified: March 3rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

Weaknesses (CWE)