CVE-2025-1731 describes an incorrect permission assignment vulnerability in Zyxel USG FLEX H series uOS firmware versions V1.20 through V1.31, specifically within PostgreSQL commands. This flaw allows an authenticated, low-privileged local attacker to gain Linux shell access and escalate privileges by crafting malicious scripts or modifying system configurations if an administrator's valid token is present. Rated 7.8 HIGH (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), the vulnerability has a local attack vector with low complexity, enabling high impact on confidentiality, integrity, and availability. Its FAUCET Risk Score is 93/100, indicating significant risk. While not currently in CISA's KEV catalog or Hot List, an exploit (EDB-52293) is publicly available on ExploitDB. There is minimal community discussion or media coverage, suggesting low public awareness despite the existence of exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.20, < 1.32CPE matchmatch criteria | cpe:2.3:o:zyxel:uos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Zyxel security advisory for incorrect permission assignment and improper privilege management vulnerabilities in USG FLEX H series firewalls
Apr 22, 2025Zyxel security advisory for incorrect permission assignment and improper privilege management vulnerabilities in USG FLEX H series firewalls
Apr 22, 2025