CVE-2025-6265
7.2Zyxel · NWA50AX PRO
A path traversal vulnerability in the file_upload-cgi program of Zyxel NWA50AX PRO firmware allows authenticated administrators to access restricted directories and delete critical system files.
Executive summary
An authenticated path traversal vulnerability in Zyxel NWA50AX PRO firmware poses a high risk by allowing administrators to delete critical system files and potentially disrupt device operations.
Vulnerability
This is a path traversal vulnerability (CWE-22) located in the file_upload-cgi CGI program. The flaw requires an attacker to possess administrator-level authentication to trigger the unauthorized file system access.
Business impact
The ability to delete configuration files or other critical system data can lead to a complete loss of device functionality or permanent denial of service. Given the CVSS score of 7.2, this vulnerability is classified as high severity, as it allows a privileged user to compromise the integrity and availability of the networking infrastructure.
Remediation
Immediate Action: Update the Zyxel NWA50AX PRO firmware to the latest version provided in the official Zyxel security advisory.
Proactive Monitoring: Review administrative access logs for unauthorized attempts to access or modify system files using the file_upload-cgi interface.
Compensating Controls: Restrict administrative access to the device management interface to trusted internal IP addresses only.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit or proof-of-concept available in the provided data.
Analyst recommendation
The risk associated with this vulnerability is significant due to the potential for total system impact. Administrators should prioritize applying the vendor-supplied firmware update to all affected NWA50AX PRO units immediately to prevent potential misuse of the administrative interface.