Products: 6
    Vulnerabilities: 7
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-69431

    The ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following. Attackers can format a USB drive to ext4, create a symbolic link to its root directory, insert the drive into the NAS device's slot, and then access the USB drive's directory mounted on the NAS using the Samba protocol. This allows them to obtain all files within the NAS system and tamper with those files.

    Last Modified: Feb 11, 2026
    Published: Feb 03, 2026

    CVE-2025-15133

    ZSPACE Z4Pro+ HTTP POST Request close zfilev2_api_CloseSafe command injection

    Last Modified: Jan 07, 2026
    Published: Dec 28, 2025

    CVE-2025-15132

    ZSPACE Z4Pro+ HTTP POST Request open zfilev2_api_open command injection

    Last Modified: Jan 07, 2026
    Published: Dec 28, 2025

    CVE-2025-15131

    ZSPACE Z4Pro+ HTTP POST Request status zfilev2_api_SafeStatus command injection

    Last Modified: Jan 07, 2026
    Published: Dec 28, 2025

    CVE-2025-14108

    ZSPACE Q2C NAS HTTP POST Request open zfilev2_api.OpenSafe command injection

    Last Modified: Dec 16, 2025
    Published: Dec 05, 2025
    Items Per Page