CVE-2025-41366
BaseFortify
Publication date: 2025-06-06
Last updated on: 2025-06-06
Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-942 | The product uses a web-client protection mechanism such as a Content Security Policy (CSP) or cross-domain policy file, but the policy includes untrusted domains with which the web client is allowed to communicate. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a configuration error in cross-origin resource sharing (CORS) in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. To exploit it, an attacker must authenticate to the device and execute certain commands that require permissions higher than view-only access.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow an authenticated user with elevated permissions to perform unauthorized actions due to improper CORS configuration, potentially leading to security risks such as unauthorized command execution.