Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-41366— CORS vulnerability in IDF and ZLF

EPSS 0.26% · P49
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-41366

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CORS vulnerability in IDF and ZLF
Source: NVD (National Vulnerability Database)
Vulnerability Description
In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing (CORS). Exploiting this vulnerability requires authenticating to the device and executing certain commands that can only be executed with permissions higher than the view permission.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
过度许可的跨域白名单
Source: NVD (National Vulnerability Database)
Vulnerability Title
ZIV IDF和ZIV ZLF 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ZIV IDF和ZIV ZLF都是西班牙ZIV的一款变压器差动保护继电器。 ZIV IDF v0.10.0-0C03-03版本和ZLF v0.10.0-0C03-04版本存在安全漏洞,该漏洞源于跨资源共享配置错误。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
ZIVIDF and ZLF 0 ~ 1.1.0 -

II. Public POCs for CVE-2025-41366

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-41366

登录查看更多情报信息。

Same Patch Batch · ZIV · 2025-06-06 · 8 CVEs total

CVE-2025-41360Uncontrolled resource consumption vulnerability in IDF and ZLF
CVE-2025-41364Stored Cross-Site Scripting (XSS) vulnerability in IDF and ZLF
CVE-2025-41365Code injection vulnerability in IDF and ZLF
CVE-2025-41363CORS vulnerability in IDF and ZLF
CVE-2025-41362Code injection vulnerability in IDF and ZLF
CVE-2025-41361Uncontrolled resource consumption vulnerability in IDF and ZLF
CVE-2025-41367Stored Cross-Site Scripting (XSS) vulnerability in IDF and ZLF

IV. Related Vulnerabilities

V. Comments for CVE-2025-41366

No comments yet


Leave a comment