CVE-2025-6265: Path Traversal
A path traversal vulnerability in the fileupload-cgi CGI program of Zyxel NWA50AX PRO firmware version 7.10(ACGE.2) and earlier could allow an authenticated attacker with administrator privileges to access specific directories and delete files, such as the configuration file, on the affected device.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zyxel NWA50AX PRO firmwareto a version that resolves this vulnerability.Fixed in 7.10(ACGE.2) and earlier
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6265?
The severity of CVE-2025-6265 is considered high due to the potential for an authenticated attacker to access and delete critical files.
How do I fix CVE-2025-6265?
To fix CVE-2025-6265, update the Zyxel NWA50AX PRO firmware to a version later than 7.10(ACGE.2) that addresses this vulnerability.
Who is affected by CVE-2025-6265?
CVE-2025-6265 affects users of Zyxel NWA50AX PRO using firmware version 7.10(ACGE.2) and earlier.
What type of vulnerability is CVE-2025-6265?
CVE-2025-6265 is a path traversal vulnerability that allows unauthorized file access and deletion.
What can an attacker do with CVE-2025-6265?
An attacker with administrator privileges can exploit CVE-2025-6265 to access specific directories and delete files including the configuration file.