← Vulnerability feed

Vulnerability record · CVE-2025-9133 · published 21 October 2025

CVE-2025-9133: Zyxel zld missing authorization vulnerability

Zyxel · Zld

A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 through V5.40, USG FLEX 50(W) series firmware versions from V4.16 through V5.40, and USG20(W)-VPN series firmware versions from V4.16 through V5.40 could allow a semi-authenticated attacker—who has completed only the first stage of the two-factor authentication (2FA) process—to view and download the system configuration from an affected device.

8.1 CVSS 3.1 High EPSS 5.5% · top 7.5% CWE-862 · Missing authorization
8.1CVSS 3.1 base score
5.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 through V5.40, USG FLEX 50(W) series firmware versions from V4.16 through V5.40, and USG20(W)-VPN series firmware versions from V4.16 through V5.40 could allow a semi-authenticated attacker—who has completed only the first stage of the two-factor authentication (2FA) process—to view and download the system configuration from an affected device.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-9133 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-11667Zyxel Firewall Web Management Path Traversal Allows File Upload and DownloadA path traversal flaw in the web management interface of multiple Zyxel firewall firmware lines (ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN) lets an…KEVEPSS 2.9%analysed9.8CVE-2020-25014Zyxel zld out-of-bounds write vulnerabilityA stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows r…EPSS 4.4%8.1CVE-2024-42057Zyxel zld os command injection vulnerabilityA command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware v…EPSS 1.3%7.5CVE-2024-42058Zyxel zld null pointer dereference vulnerabilityA null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50…EPSS 0.62%7.5CVE-2023-4398Zyxel zld integer overflow vulnerabilityAn integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ATP series firmware versions …EPSS 0.88%7.2CVE-2025-8078Zyxel zld os command injection vulnerabilityA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versio…EPSS 1.4%7.2CVE-2024-7203Zyxel zld os command injection vulnerabilityA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware ver…EPSS 1.3%7.2CVE-2024-42059Zyxel zld os command injection vulnerabilityA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versio…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2025-9133), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.