๐Ÿ” CVE Alert

CVE-2025-1732

MEDIUM 6.7
CVSS Score
6.7
EPSS Score
0.0%
EPSS Percentile
0th

An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges on a vulnerable device.

CWE CWE-269
Vendor zyxel
Product usg flex h series uos firmware
Published Apr 22, 2025
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for zyxel usg flex h series uos firmware

Be the first to know when new medium vulnerabilities affecting zyxel usg flex h series uos firmware are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Zyxel / USG FLEX H series uOS firmware
<= V1.31

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
zyxel.com: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-incorrect-permission-assignment-and-improper-privilege-management-vulnerabilities-in-usg-flex-h-series-firewalls-04-22-2025