CVE-2025-9133

8.1

Zyxel · ATP series, USG FLEX series, USG20(W)-VPN series

A missing authorization flaw in various Zyxel firewall firmware versions allows semi-authenticated attackers to access and download sensitive system configurations.

Executive summary

A missing authorization vulnerability in multiple Zyxel firewall series exposes system configurations to attackers who have partially completed two-factor authentication.

Vulnerability

The vulnerability, classified as CWE-862, permits an attacker who has successfully completed the first stage of a two-factor authentication process to bypass remaining authorization checks. This allows the unauthorized viewing and downloading of the device system configuration file.

Business impact

Successful exploitation of this vulnerability poses a significant risk to organizational security, as the system configuration file often contains sensitive information such as VPN credentials, network topology details, and administrative settings. With a CVSS score of 8.1, this flaw is categorized as High severity and could facilitate deeper network penetration or facilitate further attacks. Unauthorized access to these files may lead to total compromise of the internal network infrastructure and loss of confidentiality.

Remediation

Immediate Action: Review the official Zyxel security advisory provided in the references section and apply the latest firmware updates as soon as they are made available by the vendor.

Proactive Monitoring: Monitor firewall access logs for unusual or unauthorized attempts to access configuration interfaces, particularly those occurring between the first and second stages of multi-factor authentication.

Compensating Controls: Restrict administrative access to the management interface by limiting source IP addresses to trusted management subnets or VPN tunnels to reduce the attack surface.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the High severity of this vulnerability, administrators should prioritize identifying all affected Zyxel devices within their environment. Monitor the Zyxel security portal closely for the release of patches and verify that all management interfaces are properly firewalled from public exposure until updates can be deployed.

More Zyxel CVEs

Sources