Zspace develops a focused product line centered on network-attached storage and professional display systems, including its Q2C NAS and Z4Pro display product families. The recurring vulnerability profile reflects command and injection handling weaknesses endemic to embedded firmware and device management interfaces, particularly output encoding and special-character neutralization defects and improper file-access controls. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zspace over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14107HIGH A security flaw has been discovered in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this vulnerability is the function zfilev2_api.SafeStatus of the file /v2/file/safe/status of t | Dec 5, 2025 | 8.8 | 34 | NO | NO |
CVE-2025-14106HIGH A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected is the function zfilev2_api.CloseSafe of the file /v2/file/safe/close of the component HTTP POST Reques | Dec 5, 2025 | 8.8 | 34 | NO | NO |
CVE-2025-14108HIGH A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this issue is the function zfilev2_api.OpenSafe of the file /v2/file/safe/open of the component HTTP | Dec 5, 2025 | 8.8 | 32 | NO | NO |
CVE-2025-15133HIGH A vulnerability was identified in ZSPACE Z4Pro+ 1.0.0440024. The impacted element is the function zfilev2_api_CloseSafe of the file /v2/file/safe/close of the component HTTP POST R | Dec 28, 2025 | 8.8 | 31 | NO | NO |
CVE-2025-15131HIGH A vulnerability was found in ZSPACE Z4Pro+ 1.0.0440024. Impacted is the function zfilev2_api_SafeStatus of the file /v2/file/safe/status of the component HTTP POST Request Handler. | Dec 28, 2025 | 8.8 | 31 | NO | NO |
CVE-2025-15132HIGH A vulnerability was determined in ZSPACE Z4Pro+ 1.0.0440024. The affected element is the function zfilev2_api_open of the file /v2/file/safe/open of the component HTTP POST Request | Dec 28, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-69431MEDIUM The ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following. Attackers can format a USB drive to ext4, create a symbolic link to its root directory, in | Feb 3, 2026 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zspace.
Media articles that mention a CVE ID that affects a product developed by Zspace — matched by CVE ID, not by vendor name.