CVE-2025-15083
A vulnerability was determined in TOZED ZLT M30s up to 1.47. The affected element is an unknown function of the component UART Interface. Executing manipulation can lead to on-chip debug and test interface with improper access control. The physical device can be targeted for the attack. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- LOW
- CVSS base score
- 2
- CVSS vector
- CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.26%
- CWE
- CWE-1191
- Published
- 2025-12-25
- Last modified
- 2026-03-12
Affected products
- TOZED ZLT M30s
- TOZED ZLT M30s
- TOZED ZLT M30s
- TOZED ZLT M30s
- TOZED ZLT M30s
- TOZED ZLT M30s
- TOZED ZLT M30s
- TOZED ZLT M30s
Weakness type
Related vulnerabilities
- CVE-2026-15203 — Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software
- CVE-2026-8989 — Open Recovery Mode
- CVE-2026-8988 — Access to Bootloader
- CVE-2024-36319 — Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to...
- CVE-2025-52533 — Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a...
- CVE-2025-36755 — CleverDisplay BlueOne unauthorized BIOS access through physical USB keyboard
- CVE-2025-12114 — Serial Console Enabled
- CVE-2025-9709 — NRF52810 Runtime EM Fault Injection APPROTECT Bypass