CVE-2025-15082

A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post of the component Web Management Interface. Performing manipulation of the argument goformId results in information disclosure. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://vuldb.com/?ctiid.338410 Permissions Required VDB Entry
https://vuldb.com/?id.338410 Third Party Advisory VDB Entry
https://vuldb.com/?submit.707306 Third Party Advisory VDB Entry
https://www.hacklab.eu.org/blogs/zlt_m30s_information_disclosure Exploit Third Party Advisory
https://youtu.be/u_H29UdiPOc Exploit
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:gztozed:zlt_m30s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gztozed:zlt_m30s:-:*:*:*:*:*:*:*

History

20 Jan 2026, 19:54

Type Values Removed Values Added
CPE cpe:2.3:o:gztozed:zlt_m30s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gztozed:zlt_m30s:-:*:*:*:*:*:*:*
First Time Gztozed zlt M30s
Gztozed zlt M30s Firmware
Gztozed
References () https://vuldb.com/?ctiid.338410 - () https://vuldb.com/?ctiid.338410 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.338410 - () https://vuldb.com/?id.338410 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.707306 - () https://vuldb.com/?submit.707306 - Third Party Advisory, VDB Entry
References () https://www.hacklab.eu.org/blogs/zlt_m30s_information_disclosure - () https://www.hacklab.eu.org/blogs/zlt_m30s_information_disclosure - Exploit, Third Party Advisory
References () https://youtu.be/u_H29UdiPOc - () https://youtu.be/u_H29UdiPOc - Exploit
CWE NVD-CWE-noinfo

25 Dec 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-25 17:15

Updated : 2026-01-20 19:54


NVD link : CVE-2025-15082

Mitre link : CVE-2025-15082

CVE.ORG link : CVE-2025-15082


JSON object : View

Products Affected

gztozed

  • zlt_m30s
  • zlt_m30s_firmware
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-284

Improper Access Control

NVD-CWE-noinfo