Products: 6
Vulnerabilities: 7
Known Exploited: 0
0
Critical Level Threats
3
High Level Threats
4
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2025-69431
The ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following. Attackers can format a USB drive to ext4, create a symbolic link to its root directory, insert the drive into the NAS device's slot, and then access the USB drive's directory mounted on the NAS using the Samba protocol. This allows them to obtain all files within the NAS system and tamper with those files.
Last Modified: Feb 11, 2026
Published: Feb 03, 2026
CVE-2025-15133
ZSPACE Z4Pro+ HTTP POST Request close zfilev2_api_CloseSafe command injection
Last Modified: Jan 07, 2026
Published: Dec 28, 2025
CVE-2025-15132
ZSPACE Z4Pro+ HTTP POST Request open zfilev2_api_open command injection
Last Modified: Jan 07, 2026
Published: Dec 28, 2025
CVE-2025-15131
ZSPACE Z4Pro+ HTTP POST Request status zfilev2_api_SafeStatus command injection
Last Modified: Jan 07, 2026
Published: Dec 28, 2025
CVE-2025-14108
ZSPACE Q2C NAS HTTP POST Request open zfilev2_api.OpenSafe command injection
Last Modified: Dec 16, 2025
Published: Dec 05, 2025
Items Per Page
