CVE-2025-14106High· 8.8▾ TwilightA vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected is the function zfilev2_api.CloseSafe of the file /v2/file/safe/close of the component HTTP POST Request Handler. The manipulation of the argument safe_dir lead…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 2.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
12%
A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected is the function zfilev2_api.CloseSafe of the file /v2/file/safe/close of the component HTTP POST Request Handler. The manipulation of the argument safe_dir leads to command injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. A technical fix is planned to be released.
q2c_nas_firmware <= 1.1.0210050Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14108High· 8.8A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050
CVE-2025-14107High· 8.8A security flaw has been discovered in ZSPACE Q2C NAS up to 1.1.0210050
CVE-2025-9582Medium· 6.3A flaw has been found in Comfast CF-N1 2.6.0
CVE-2025-9581Medium· 6.3A vulnerability was detected in Comfast CF-N1 2.6.0
CVE-2025-15391Medium· 6.3A weakness has been identified in D-Link DIR-806A 100CNb11
CVE-2025-13799Medium· 6.3A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c