7.2

CVE-2025-6265

A path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware version 7.10(ACGE.2) and earlier could allow an authenticated attacker with administrator privileges to access specific directories and delete files, such as the configuration file, on the affected device.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZyxelNwa50ax Firmware Version <= 7.10\(abyw.1\)
   ZyxelNwa50ax Version-
ZyxelNwa50ax Pro Firmware Version <= 7.10\(acge.2\)
   ZyxelNwa50ax Pro Version-
ZyxelNwa55axe Firmware Version <= 7.10\(abzl.1\)
   ZyxelNwa55axe Version-
ZyxelNwa90ax Firmware Version <= 7.10\(accv.1\)
   ZyxelNwa90ax Version-
ZyxelNwa90ax Pro Firmware Version <= 7.10\(acgf.2\)
   ZyxelNwa90ax Pro Version-
ZyxelNwa110ax Firmware Version <= 7.10\(abtg.1\)
   ZyxelNwa110ax Version-
ZyxelNwa130be Firmware Version <= 7.10\(acil.2\)
   ZyxelNwa130be Version-
ZyxelNwa210ax Firmware Version <= 7.10\(abtd.1\)
   ZyxelNwa210ax Version-
ZyxelNwa220ax-6e Firmware Version <= 7.10\(acco.1\)
   ZyxelNwa220ax-6e Version-
ZyxelNwa1123ac Pro Firmware Version <= 6.28\(abhd.3\)
   ZyxelNwa1123ac Pro Version-
ZyxelWac500h Firmware Version <= 6.70\(abwa.6\)
   ZyxelWac500h Version-
ZyxelWac5302d-sv2 Firmware Version <= 6.25\(abvz.9\)
   ZyxelWac5302d-sv2 Version-
ZyxelWac6103d-i Firmware Version <= 6.28\(aaxh.3\)
   ZyxelWac6103d-i Version-
ZyxelWax300h Firmware Version <= 7.10\(achf.1\)
   ZyxelWax300h Version-
ZyxelWax510d Firmware Version <= 7.10\(abtf.1\)
   ZyxelWax510d Version-
ZyxelWax610d Firmware Version <= 7.10\(abte.1\)
   ZyxelWax610d Version-
ZyxelWax620d-6e Firmware Version <= 7.10\(accn.1\)
   ZyxelWax620d-6e Version-
ZyxelWax630s Firmware Version <= 7.10\(abzd.1\)
   ZyxelWax630s Version-
ZyxelWax640s-6e Firmware Version <= 7.10\(accm.1\)
   ZyxelWax640s-6e Version-
ZyxelWax650s Firmware Version <= 7.10\(abrm.1\)
   ZyxelWax650s Version-
ZyxelWax655e Firmware Version <= 7.10\(acdo.1\)
   ZyxelWax655e Version-
ZyxelWbe530 Firmware Version <= 7.10\(acle.2\)
   ZyxelWbe530 Version-
ZyxelWbe660s Firmware Version <= 7.10\(acgg.2\)
   ZyxelWbe660s Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.316
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@zyxel.com.tw 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.