CVE-2025-3577

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 22

Summary

CVE-2025-3577 is a path traversal vulnerability affecting the web management interface of Zyxel AMG1302-T10B firmware version 2.00(AAJC.16)C0. An authenticated attacker with administrator privileges can exploit this vulnerability by sending a carefully crafted HTTP request to an affected device. If successful, the attacker could gain unauthorized access to restricted directories. This issue is significant as it can potentially lead to data exposure or unauthorized system modifications. It is essential that affected device users apply the necessary patches or updates as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share