A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote unauthenticated attackers to access administrative information-retrieval functions intended for authenticated users. By invoking "get_*" operations, attackers can obtain device configuration data, including plaintext credentials, without authentication or an existing session.
References
Configurations
No configuration.
History
17 Feb 2026, 22:18
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
12 Feb 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-287 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
11 Feb 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-11 17:16
Updated : 2026-02-17 22:18
NVD link : CVE-2025-65127
Mitre link : CVE-2025-65127
CVE.ORG link : CVE-2025-65127
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
