8.1

CVE-2025-9133

Medienbericht
A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 through V5.40, USG FLEX 50(W) series firmware versions from V4.16 through V5.40, and USG20(W)-VPN series firmware versions from V4.16 through V5.40 could allow a semi-authenticated attacker—who has completed only the first stage of the two-factor authentication (2FA) process—to view and download the system configuration from an affected device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZyxelZld Version >= 4.32 < 5.41
   ZyxelAtp100 Version-
   ZyxelAtp100w Version-
   ZyxelAtp200 Version-
   ZyxelAtp500 Version-
   ZyxelAtp700 Version-
   ZyxelAtp800 Version-
ZyxelZld Version >= 4.50 < 5.41
   ZyxelUsg Flex 100 Version-
   ZyxelUsg Flex 100ax Version-
   ZyxelUsg Flex 100w Version-
   ZyxelUsg Flex 200 Version-
   ZyxelUsg Flex 50 Version-
   ZyxelUsg Flex 500 Version-
   ZyxelUsg Flex 50ax Version-
   ZyxelUsg Flex 700 Version-
ZyxelZld Version >= 4.16 < 5.41
   ZyxelUsg 20w-vpn
   ZyxelUsg Flex 50w Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.152
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@zyxel.com.tw 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.