Vulnerability Details CVE-2025-1732
An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges on a vulnerable device.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 2.6%
CVSS Severity
CVSS v3 Score 6.7
Products affected by CVE-2025-1732
-
cpe:2.3:h:zyxel:usg_flex_100h:-
-
cpe:2.3:h:zyxel:usg_flex_100hp:-
-
cpe:2.3:h:zyxel:usg_flex_200h:-
-
cpe:2.3:h:zyxel:usg_flex_200hp:-
-
cpe:2.3:h:zyxel:usg_flex_500h:-
-
cpe:2.3:h:zyxel:usg_flex_50h:-
-
cpe:2.3:h:zyxel:usg_flex_50hp:-
-
cpe:2.3:h:zyxel:usg_flex_700h:-
-