CVE-2025-1732

An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges on a vulnerable device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zyxel:uos:1.31:*:*:*:*:*:*:*
OR cpe:2.3:h:zyxel:usg_flex_100h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_100hp:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_200h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_200hp:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_500h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_50h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_50hp:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_700h:-:*:*:*:*:*:*:*

History

30 Oct 2025, 17:56

Type Values Removed Values Added
References () https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-incorrect-permission-assignment-and-improper-privilege-management-vulnerabilities-in-usg-flex-h-series-firewalls-04-22-2025 - () https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-incorrect-permission-assignment-and-improper-privilege-management-vulnerabilities-in-usg-flex-h-series-firewalls-04-22-2025 - Vendor Advisory
First Time Zyxel usg Flex 50h
Zyxel
Zyxel usg Flex 700h
Zyxel uos
Zyxel usg Flex 500h
Zyxel usg Flex 100hp
Zyxel usg Flex 100h
Zyxel usg Flex 50hp
Zyxel usg Flex 200h
Zyxel usg Flex 200hp
CPE cpe:2.3:h:zyxel:usg_flex_200hp:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_50h:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:uos:1.31:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_100hp:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_100h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_700h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_50hp:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_200h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_500h:-:*:*:*:*:*:*:*

Information

Published : 2025-04-22 03:15

Updated : 2025-10-30 17:56


NVD link : CVE-2025-1732

Mitre link : CVE-2025-1732

CVE.ORG link : CVE-2025-1732


JSON object : View

Products Affected

zyxel

  • usg_flex_200h
  • usg_flex_50h
  • usg_flex_500h
  • usg_flex_50hp
  • usg_flex_200hp
  • usg_flex_100h
  • usg_flex_100hp
  • uos
  • usg_flex_700h
CWE
CWE-269

Improper Privilege Management