CVE-2025-64427 | IceWhaleTech ZimaOS up to 1.4.x URL server-side request forgery
A vulnerability marked as critical has been reported in IceWhaleTech ZimaOS up to 1.4.x. Affected by this issue is some unknown functionality of the component URL Handler. This manipulation causes server-side request forgery.
This vulnerability is registered as CVE-2025-64427. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.