An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges on a vulnerable device.
                
            References
                    Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    30 Oct 2025, 17:56
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Zyxel Zyxel usg Flex 200hp Zyxel usg Flex 50hp Zyxel usg Flex 50h Zyxel uos Zyxel usg Flex 700h Zyxel usg Flex 200h Zyxel usg Flex 100hp Zyxel usg Flex 500h Zyxel usg Flex 100h | |
| CPE | cpe:2.3:h:zyxel:usg_flex_200hp:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_500h:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_100h:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_200h:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:uos:1.31:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_700h:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_50hp:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_50h:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_100hp:-:*:*:*:*:*:*:* | |
| References | () https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-incorrect-permission-assignment-and-improper-privilege-management-vulnerabilities-in-usg-flex-h-series-firewalls-04-22-2025 - Vendor Advisory | 
12 Jun 2025, 07:15
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | (en) An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges on a vulnerable device. | 
23 Apr 2025, 14:08
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
22 Apr 2025, 03:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-04-22 03:15
Updated : 2025-10-30 17:56
NVD link : CVE-2025-1732
Mitre link : CVE-2025-1732
CVE.ORG link : CVE-2025-1732
JSON object : View
Products Affected
                zyxel
- usg_flex_500h
- usg_flex_100hp
- usg_flex_50hp
- usg_flex_700h
- uos
- usg_flex_200h
- usg_flex_50h
- usg_flex_100h
- usg_flex_200hp
CWE
                
                    
                        
                        CWE-269
                        
            Improper Privilege Management
