Description
A vulnerability has been found in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. Affected is an unknown function of the component Web Interface. Such manipulation leads to hard-coded credentials. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Problem types
Product status
3.09.06
3.09.06
Timeline
| 2025-12-05: | Advisory disclosed |
| 2025-12-05: | VulDB entry created |
| 2025-12-05: | VulDB entry last update |
Credits
S33K3R (VulDB User)
References
vuldb.com/?id.334521 (VDB-334521 | TOZED ZLT M30S/ZLT M30S PRO Web hard-coded credentials)
vuldb.com/?ctiid.334521 (VDB-334521 | CTI Indicators (IOB, IOC, TTP))
vuldb.com/?submit.697498 (Submit #697498 | ZLT M30S & M30S PRO MTNNGRM30S_1.47, M30SPRO_3.09.06 (Other versions might be vulnerable) Backdoor Credentials)
youtu.be/o8rfjSlpRxY