8.7
/ 10
HIGH
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Description
A vulnerability has been found in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. Affected is an unknown function of the component Web Interface. Such manipulation leads to hard-coded credentials. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
AI Analysis
Hard-coded credentials vulnerability in the Web Interface of TOZED ZLT M30S and ZLT M30S PRO
Basic Information
ID
CVE-2025-14126
Source
VulDB
Published
Dec 6, 2025 at 10:02
Affected Product
Vendor
TOZED
Product
ZLT M30S
Version
1.47
Affected Versions
TOZED ZLT M30S 1.47
TOZED ZLT M30S 3.09.06
TOZED ZLT M30S PRO 1.47
TOZED ZLT M30S PRO 3.09.06
TOZED ZLT M30S 3.09.06
TOZED ZLT M30S PRO 1.47
TOZED ZLT M30S PRO 3.09.06
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
TOZED
Product
ZLT M30S
Version
1.47, 3.09.06