An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges on a vulnerable device.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 30 Oct 2025 18:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Zyxel Zyxel uos Zyxel usg Flex 100h Zyxel usg Flex 100hp Zyxel usg Flex 200h Zyxel usg Flex 200hp Zyxel usg Flex 500h Zyxel usg Flex 50h Zyxel usg Flex 50hp Zyxel usg Flex 700h | |
| CPEs | cpe:2.3:h:zyxel:usg_flex_100h:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_100hp:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_200h:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_200hp:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_500h:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_50h:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_50hp:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_700h:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:uos:1.31:*:*:*:*:*:*:* | |
| Vendors & Products | Zyxel Zyxel uos Zyxel usg Flex 100h Zyxel usg Flex 100hp Zyxel usg Flex 200h Zyxel usg Flex 200hp Zyxel usg Flex 500h Zyxel usg Flex 50h Zyxel usg Flex 50hp Zyxel usg Flex 700h | 
Thu, 12 Jun 2025 07:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An improper privilege management vulnerability in the recovery function of the USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges on a vulnerable device. | An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges on a vulnerable device. | 
Tue, 22 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Tue, 22 Apr 2025 02:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An improper privilege management vulnerability in the recovery function of the USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges on a vulnerable device. | |
| Weaknesses | CWE-269 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Zyxel
Published:
Updated: 2025-06-12T07:05:39.793Z
Reserved: 2025-02-27T03:13:45.776Z
Link: CVE-2025-1732
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-04-22T13:32:56.702Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-04-22T03:15:21.337
Modified: 2025-10-30T17:56:11.717
Link: CVE-2025-1732
 Redhat
                        Redhat
                    No data.