A vulnerability has been found in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. Affected is an unknown function of the component Web Interface. Such manipulation leads to hard-coded credentials. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Sat, 06 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. Affected is an unknown function of the component Web Interface. Such manipulation leads to hard-coded credentials. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | TOZED ZLT M30S/ZLT M30S PRO Web hard-coded credentials | |
| Weaknesses | CWE-259 CWE-798 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-12-06T10:02:05.279Z
Updated: 2025-12-06T10:02:05.279Z
Reserved: 2025-12-05T16:58:25.370Z
Link: CVE-2025-14126
No data.
Status : Received
Published: 2025-12-06T10:16:05.297
Modified: 2025-12-06T10:16:05.297
Link: CVE-2025-14126
No data.