CVE-2025-3577
CVSS 3.1 Score 4.9 of 10 (medium)
Details
Summary
CVE-2025-3577 is a path traversal vulnerability affecting the web management interface of Zyxel AMG1302-T10B firmware version 2.00(AAJC.16)C0. An authenticated attacker with administrator privileges can exploit this vulnerability by sending a carefully crafted HTTP request to an affected device. If successful, the attacker could gain unauthorized access to restricted directories. This issue is significant as it can potentially lead to data exposure or unauthorized system modifications. It is essential that affected device users apply the necessary patches or updates as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- ZyXEL