CVE-2025-1732

An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges on a vulnerable device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zyxel:uos:1.31:*:*:*:*:*:*:*
OR cpe:2.3:h:zyxel:usg_flex_100h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_100hp:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_200h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_200hp:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_500h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_50h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_50hp:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_700h:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-04-22 03:15

Updated : 2025-10-30 17:56


NVD link : CVE-2025-1732

Mitre link : CVE-2025-1732

CVE.ORG link : CVE-2025-1732


JSON object : View

Products Affected

zyxel

  • usg_flex_500h
  • usg_flex_50hp
  • usg_flex_50h
  • usg_flex_700h
  • usg_flex_100h
  • usg_flex_200h
  • usg_flex_200hp
  • uos
  • usg_flex_100hp
CWE
CWE-269

Improper Privilege Management