VYPR
Vendor

Icewhaletech

Products
3
CVEs
17
Across products
17
Status
Private

Products

3

Recent CVEs

17
  • CVE-2026-21891CriJan 8, 2026
    risk 0.61cvss 9.4epss 0.02

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application checks the validity of the username but appears to skip, misinterpret, or incorrectly validate the password when the provided…

  • CVE-2023-37266CriJul 17, 2023
    risk 0.57cvss 9.8epss 0.07

    CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication and execute arbitrary commands as `root` on CasaOS instances. This problem was addressed by improving the validation of JWTs…

  • CVE-2026-28442HigMar 5, 2026
    risk 0.55cvss 8.5epss 0.00

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, users are restricted from deleting internal system files or folders through the application interface. However, when interacting directly with the API, these…

  • CVE-2026-28286HigMar 2, 2026
    risk 0.55cvss 8.5epss 0.00

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, the application enforces restrictions in the frontend/UI to prevent users from creating files or folders in internal OS paths. However, when interacting…

  • CVE-2024-24767CriMar 6, 2024
    risk 0.52cvss 9.1epss 0.01

    CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, CasaOS doesn't defend against password brute force attacks, which leads to having full access to the server. The web application lacks control over the…

  • CVE-2025-58432HigSep 17, 2025
    risk 0.51cvss 7.8epss 0.00

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and all prior versions, the /v2_1/files/file/uploadV2 endpoint allows file upload from ANY USER who has access to localhost. File uploads are performed AS ROOT.

  • CVE-2024-49357HigOct 24, 2024
    risk 0.50cvss 7.5epss 0.24

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoints in ZimaOS, such as `http:///v1/users/image?path=/var/lib/casaos/1/app_order.json` and…

  • CVE-2023-37469HigAug 24, 2023
    risk 0.50cvss 8.8epss 0.01

    CasaOS is an open-source personal cloud system. Prior to version 0.4.4, if an authenticated user using CasaOS is able to successfully connect to a controlled SMB server, they are able to execute arbitrary commands. Version 0.4.4 contains a patch for the issue.

  • CVE-2024-49359HigOct 24, 2024
    risk 0.49cvss 7.5epss 0.01

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Zima_Server_IP:PORT>/v2_1/file` in ZimaOS is vulnerable to a directory traversal attack, allowing authenticated users…

  • CVE-2024-48931HigOct 24, 2024
    risk 0.49cvss 7.5epss 0.01

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the ZimaOS API endpoint `http://<Zima_Server_IP:PORT>/v3/file?token=&files=<file_path>` is vulnerable to arbitrary file reading due to…

  • CVE-2025-64427HigMar 2, 2026
    risk 0.46cvss 7.1epss 0.00

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prior, due to insufficient validation or restriction of target URLs, an authenticated local user can craft requests that target internal IP addresses (e.g.,…

  • CVE-2024-24765HigMar 6, 2024
    risk 0.42cvss 7.5epss 0.01

    CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL for user avatar image files was not strict, making it possible to get any file on the system. This could allow an unauthorized actor to access, for example,…

  • CVE-2025-58431MedSep 17, 2025
    risk 0.40cvss 6.2epss 0.00

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and earlier, the /v2_1/files/file/download endpoint allows file read from ANY USER who has access to localhost. File reads are performed AS ROOT.

  • CVE-2024-49358MedOct 24, 2024
    risk 0.34cvss 5.3epss 0.00

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http:///v1/users/login` in ZimaOS returns distinct responses based on whether a username exists or the password is…

  • CVE-2024-48932MedOct 24, 2024
    risk 0.34cvss 5.3epss 0.01

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions below 1.5.0, the API endpoint `http:///v1/users/name` allows unauthenticated users to access sensitive information, such as usernames, without any authorization.…

  • CVE-2024-28232MedApr 1, 2024
    risk 0.33cvss 6.2epss 0.01

    Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which was patched in version 0.4.7. This issue in CVE-2024-28232 has been patched in…

  • CVE-2024-24766MedMar 6, 2024
    risk 0.33cvss 6.2epss 0.01

    CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration vulnerability in the login page. An attacker can enumerate the CasaOS username using the…