CVE-2025-9133

HIGH

Zyxel ATP-USG FLEX-20(W)-VPN - Info Disclosure

Title source: llm

Description

A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 through V5.40, USG FLEX 50(W) series firmware versions from V4.16 through V5.40, and USG20(W)-VPN series firmware versions from V4.16 through V5.40 could allow a semi-authenticated attacker—who has completed only the first stage of the two-factor authentication (2FA) process—to view and download the system configuration from an affected device.

Scores

CVSS v3 8.1
EPSS 0.0008
EPSS Percentile 24.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Classification

CWE
CWE-862
Status published

Affected Products (1)

zyxel/zld < 5.41

Timeline

Published Oct 21, 2025
Tracked Since Feb 18, 2026