CVE-2025-41363
BaseFortify
Publication date: 2025-06-06
Last updated on: 2025-06-06
Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-942 | The product uses a web-client protection mechanism such as a Content Security Policy (CSP) or cross-domain policy file, but the policy includes untrusted domains with which the web client is allowed to communicate. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a configuration error in cross-origin resource sharing (CORS) in specific versions of IDF and ZLF software. An attacker who is authenticated and has at least view permission can exploit this misconfiguration by executing certain commands, potentially leading to unauthorized actions or information disclosure.
How can this vulnerability impact me? :
The vulnerability can allow an authenticated user with limited permissions (view permission) to execute certain commands that they should not normally be able to, potentially leading to unauthorized access or actions within the affected device.