CVE-2025-12917 is a denial-of-service vulnerability affecting TOZED ZLT T10 firmware version T10PLUS_3.04.15. The issue is reported in an unspecified function within the /reqproc/proc_post endpoint of the device's Reboot Handler component. By sending a crafted request to this handler, an attacker on the local network can trigger a condition that causes service disruption or device instability. Public exploit code is reported to be available. The precise root cause and vulnerable function are not disclosed in the available information, so the weakness classification is based on the reported crafted-input handling behavior.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Python script (CVE-2025-12917.py) that exploits CVE-2025-12917. The script sends an unauthenticated HTTP GET request to a specific endpoint on a device at 192.168.8.1, which is likely a router or similar network device. If the device is vulnerable, this request will trigger a reboot. The exploit is a simple proof-of-concept and does not include any authentication or advanced payloads. The only endpoint targeted is the hardcoded local network IP with a specific reboot command. The repository is minimal, containing only the exploit script, and is intended to demonstrate the vulnerability rather than provide a weaponized or operational exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.