Zimaspace's vulnerability profile concentrates on ZimaOS, a storage and media operating system positioned prominently in the embedded and consumer NAS landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a marked tendency toward public exploit availability, reflecting the product's internet-facing management interfaces and the privilege-escalation and access-control gaps that recur across its attack surface—including improper privilege execution, sensitive information exposure, path traversal, and missing authorization checks. Defenders should prioritize patches for this vendor's storage appliances, particularly those exposed to untrusted networks; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zimaspace over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-21891CRITICAL ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application checks the validity of the use | Jan 8, 2026 | 9.8 | 44 | NO | YES |
CVE-2024-49357HIGH ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoints in ZimaOS, such as `http:/ | Oct 24, 2024 | 7.5 | 44 | NO | YES |
CVE-2026-28798CRITICAL ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a proxy endpoint (/v1/sys/proxy) exposed by ZimaOS's web inte | Apr 3, 2026 | 10.0 | 38 | NO | NO |
CVE-2026-28286CRITICAL ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, the application enforces restrictions in the frontend/UI to p | Mar 2, 2026 | 9.9 | 34 | NO | NO |
CVE-2026-28442HIGH ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, users are restricted from deleting internal system files or f | Mar 5, 2026 | 8.5 | 29 | NO | NO |
CVE-2025-58432HIGH ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and all prior versions, the /v2_1/files/file/uploadV2 endpoint allow | Sep 17, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-64427MEDIUM ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prior, due to insufficient validation or restriction of target U | Mar 2, 2026 | 6.5 | 24 | NO | NO |
CVE-2025-58431MEDIUM ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and earlier, the /v2_1/files/file/download endpoint allows file read | Sep 17, 2025 | 6.2 | 21 | NO | NO |
CVE-2024-49359HIGH ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Zima_Server_IP:POR | Oct 24, 2024 | 7.5 | 20 | NO | NO |
CVE-2024-48931HIGH ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the ZimaOS API endpoint `http://<Zima_Server | Oct 24, 2024 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zimaspace.
Media articles that mention a CVE ID that affects a product developed by Zimaspace — matched by CVE ID, not by vendor name.