CVE-2025-34467
ZwiiCMS versions prior to 13.7.00 contain a denial-of-service vulnerability in multiple administrative endpoints due to improper authorization checks combined with flawed resource state management. When an authenticated low-privilege user requests an administrative page, the application returns "404 Not Found" as expected, but incorrectly acquires and associates a temporary lock on the targeted resource with the attacker session prior to authorization. This lock prevents other users, including administrators, from accessing the affected functionality until the attacker navigates away or the session is terminated.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.22%
- CWE
- CWE-667, CWE-863
- Published
- 2025-12-31
- Last modified
- 2026-07-14
Affected products
- fredtempez ZwiiCMS
Weakness type
Related vulnerabilities
- CVE-2026-80126 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-45404 — OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access
- CVE-2026-54906 — concurrent-ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption
- CVE-2026-24182 — NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak...
- CVE-2026-20065 — Multiple Cisco Products Snort 3 TBD Denial of Service Vulnerability
- CVE-2026-20757 — Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged...
- CVE-2026-21914 — Junos OS: SRX Series: A specifically malformed GTP message will cause an FPC crash
- CVE-2025-68657 — espressif/usb_host_hid Double-Free Race Condition in USB Host HID Device Close Path