CVE-2025-65128
Last modified
CVE-2025-65128 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unauthenticated attackers on the local network to modify router and network configurations. By invoking operations whose names end with "*_nocommit" and supplying the parameters expected by the invoked function, an attacker can change configuration data, including SSID, Wi-Fi credentials, and administrative passwords, without authentication or an existing session.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unauthenticated attackers on the local network to modify router and network configurations. By invoking operations whose names end with "*_nocommit" and supplying the parameters expected by the invoked function, an attacker can change configuration data, including SSID, Wi-Fi credentials, and administrative passwords, without authentication or an existing session.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-65128?
How severe is CVE-2025-65128?
How do I fix CVE-2025-65128?
Are you affected by CVE-2025-65128?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
