CVE-2025-5105
A vulnerability was found in TOZED ZLT W51 up to 1.4.2 and classified as critical. Affected by this issue is some unknown functionality of the component Service Port 7777. The manipulation leads to improper clearing of heap memory before release. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 7.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.45%
- CWE
- CWE-244
- Published
- 2025-05-23
- Last modified
- 2026-03-13
Affected products
- TOZED ZLT W51
- TOZED ZLT W51
- TOZED ZLT W51
Weakness type
Related vulnerabilities
- CVE-2026-20349 — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
- CVE-2026-48025 — nebula-mesh: Decrypted CA private key persists in heap after signing
- CVE-2026-20039 — Cisco Adaptive Security Appliance and Firepower Threat Defense Software SSL VPN Authentication Denial of Service Vulnerability
- CVE-2025-33101 — Multiple Vulnerabilities in IBM Concert Software.
- CVE-2025-1722 — Multiple Vulnerabilities in IBM Concert Software
- CVE-2025-1719 — Multiple Vulnerabilities in IBM Concert Software
- CVE-2025-1721 — BM Concert Software Improper Clearing of Heap Memory Before Release.
- CVE-2025-36118 — IBM Storage Virtualize Information Disclosure