ZSPACE records
7 published records for vendor zspace.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')6
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
33Monitor | CVE-2025-14107No exploit | ZSPACE Q2C NAS HTTP POST Request status zfilev2_api.SafeStatus command injectionzspace · q2c nas firmware · CWE-74 | High7.4 | — | 12.2% | Dec 5, 2025 |
33Monitor | CVE-2025-14106No exploit | ZSPACE Q2C NAS HTTP POST Request close zfilev2_api.CloseSafe command injectionzspace · q2c nas firmware · CWE-74 | High7.4 | — | 12.1% | Dec 5, 2025 |
32Monitor | CVE-2025-14108No exploit | ZSPACE Q2C NAS HTTP POST Request open zfilev2_api.OpenSafe command injectionzspace · q2c nas firmware · CWE-74 | High7.4 | — | 10.5% | Dec 5, 2025 |
24Monitor | CVE-2025-69431No exploit | The ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following.zspace · q2c firmware · CWE-59 | Medium6.1 | — | 0.3% | Feb 3, 2026 |
10Monitor | CVE-2025-15133No exploit | ZSPACE Z4Pro+ HTTP POST Request close zfilev2_api_CloseSafe command injectionzspace · z4pro\+ firmware · CWE-74 | Low2.1 | — | 7.9% | Dec 28, 2025 |
10Monitor | CVE-2025-15131No exploit | ZSPACE Z4Pro+ HTTP POST Request status zfilev2_api_SafeStatus command injectionzspace · z4pro\+ firmware · CWE-74 | Low2.1 | — | 7.6% | Dec 28, 2025 |
10Monitor | CVE-2025-15132No exploit | ZSPACE Z4Pro+ HTTP POST Request open zfilev2_api_open command injectionzspace · z4pro\+ firmware · CWE-74 | Low2.1 | — | 7.6% | Dec 28, 2025 |
- CVE-2025-1410733Monitor
ZSPACE Q2C NAS HTTP POST Request status zfilev2_api.SafeStatus command injection
HighCVSS 7.4No exploitEPSS 12%zspace · q2c nas firmwareDec 5, 2025
- CVE-2025-1410633Monitor
ZSPACE Q2C NAS HTTP POST Request close zfilev2_api.CloseSafe command injection
HighCVSS 7.4No exploitEPSS 12%zspace · q2c nas firmwareDec 5, 2025
- CVE-2025-1410832Monitor
ZSPACE Q2C NAS HTTP POST Request open zfilev2_api.OpenSafe command injection
HighCVSS 7.4No exploitEPSS 10%zspace · q2c nas firmwareDec 5, 2025
- CVE-2025-6943124Monitor
The ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following.
MediumCVSS 6.1No exploitEPSS 0%zspace · q2c firmwareFeb 3, 2026
- CVE-2025-1513310Monitor
ZSPACE Z4Pro+ HTTP POST Request close zfilev2_api_CloseSafe command injection
LowCVSS 2.1No exploitEPSS 8%zspace · z4pro\+ firmwareDec 28, 2025
- CVE-2025-1513110Monitor
ZSPACE Z4Pro+ HTTP POST Request status zfilev2_api_SafeStatus command injection
LowCVSS 2.1No exploitEPSS 8%zspace · z4pro\+ firmwareDec 28, 2025
- CVE-2025-1513210Monitor
ZSPACE Z4Pro+ HTTP POST Request open zfilev2_api_open command injection
LowCVSS 2.1No exploitEPSS 8%zspace · z4pro\+ firmwareDec 28, 2025