Description

An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges on a vulnerable device.

INFO

Published Date :

2025-04-22T01:57:35.395Z

Last Modified :

2026-02-26T18:28:08.391Z

Source :

Zyxel
AFFECTED PRODUCTS

The following products are affected by CVE-2025-1732 vulnerability.

Vendors Products
Zyxel
  • Uos
  • Usg Flex 100h
  • Usg Flex 100hp
  • Usg Flex 200h
  • Usg Flex 200hp
  • Usg Flex 500h
  • Usg Flex 50h
  • Usg Flex 50hp
  • Usg Flex 700h

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact