CVE-2025-12917

MEDIUM

TOZED ZLT T10 T10PLUS_3.04.15 - DoS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-12917. PoCs published by 0xcucumbersalad.

AI-analyzed exploit summary This PoC exploits an unauthenticated reboot vulnerability in a device by sending a crafted HTTP GET request to a specific endpoint. The exploit triggers a device reboot without requiring authentication.

Description

A vulnerability was identified in TOZED ZLT T10 T10PLUS_3.04.15. The affected element is an unknown function of the file /reqproc/proc_post of the component Reboot Handler. Such manipulation leads to denial of service. Access to the local network is required for this attack to succeed. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Exploits (1)

nomisec WORKING POC 1 stars
by 0xcucumbersalad · poc
https://github.com/0xcucumbersalad/CVE-2025-12917-PoC

This PoC exploits an unauthenticated reboot vulnerability in a device by sending a crafted HTTP GET request to a specific endpoint. The exploit triggers a device reboot without requiring authentication.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Unknown (likely a router or embedded device with web interface)
No auth needed
Prerequisites: Network access to the target device · Target device must be running vulnerable firmware
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
https://vuldb.com/?id.331635
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.331635
Exploit, Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.679507
Exploit exploit media-coverage
https://youtu.be/3Me3wlH5cfU

Scores

CVSS v3 4.3
EPSS 0.0052
EPSS Percentile 39.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (1)
gztozed/zlt_t10_plus_firmware 3.04.15
Published Nov 09, 2025
Tracked Since Feb 18, 2026