CVE-2025-41366

IDF v0.10.0-0C03-03/ZLF v0.10.0-0C03-04 - SSRF

Title source: llm

Description

In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing (CORS). Exploiting this vulnerability requires authenticating to the device and executing certain commands that can only be executed with permissions higher than the view permission.

Scores

EPSS 0.0007
EPSS Percentile 20.2%

Classification

CWE
CWE-942
Status draft

Timeline

Published Jun 06, 2025
Tracked Since Feb 18, 2026