CVE-2025-6265
A path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware version 7.10(ACGE.2) and earlier could allow an authenticated attacker with administrator privileges to access specific directories and delete files, such as the configuration file, on the affected device.
Published:Jul 15, 2025
Last Modified:Feb 26, 2026
EPS:Jul 15, 2025
EPSS Score:0.0013
CVSS Score:7.2
Affected Products
Vendor
Product
Action
Vendor
Zyxel
Product
Nwa110ax
Zyxel
Nwa110ax
Vendor
Zyxel
Product
Nwa110ax Firmware
Zyxel
Nwa110ax Firmware
Vendor
Zyxel
Product
Nwa1123ac Pro
Zyxel
Nwa1123ac Pro
Vendor
Zyxel
Product
Nwa1123ac Pro Firmware
Zyxel
Nwa1123ac Pro Firmware
Vendor
Zyxel
Product
Nwa130be
Zyxel
Nwa130be
Vendor
Zyxel
Product
Nwa130be Firmware
Zyxel
Nwa130be Firmware
Vendor
Zyxel
Product
Nwa210ax
Zyxel
Nwa210ax
Vendor
Zyxel
Product
Nwa210ax Firmware
Zyxel
Nwa210ax Firmware
Vendor
Zyxel
Product
Nwa220ax-6e
Zyxel
Nwa220ax-6e
Vendor
Zyxel
Product
Nwa220ax-6e Firmware
Zyxel
Nwa220ax-6e Firmware
Vendor
Zyxel
Product
Nwa50ax
Zyxel
Nwa50ax
Vendor
Zyxel
Product
Nwa50ax-pro
Zyxel
Nwa50ax-pro
Vendor
Zyxel
Product
Nwa50ax-pro Firmware
Zyxel
Nwa50ax-pro Firmware
Vendor
Zyxel
Product
Nwa50ax Firmware
Zyxel
Nwa50ax Firmware
Vendor
Zyxel
Product
Nwa50ax Pro
Zyxel
Nwa50ax Pro
Vendor
Zyxel
Product
Nwa50ax Pro Firmware
Zyxel
Nwa50ax Pro Firmware
Vendor
Zyxel
Product
Nwa55axe
Zyxel
Nwa55axe
Vendor
Zyxel
Product
Nwa55axe Firmware
Zyxel
Nwa55axe Firmware
Vendor
Zyxel
Product
Nwa90ax
Zyxel
Nwa90ax
Vendor
Zyxel
Product
Nwa90ax Firmware
Zyxel
Nwa90ax Firmware
Vendor
Zyxel
Product
Nwa90ax Pro
Zyxel
Nwa90ax Pro
Vendor
Zyxel
Product
Nwa90ax Pro Firmware
Zyxel
Nwa90ax Pro Firmware
Vendor
Zyxel
Product
Wac500h
Zyxel
Wac500h
Vendor
Zyxel
Product
Wac500h Firmware
Zyxel
Wac500h Firmware
Vendor
Zyxel
Product
Wac5302d-sv2
Zyxel
Wac5302d-sv2
Vendor
Zyxel
Product
Wac5302d-sv2 Firmware
Zyxel
Wac5302d-sv2 Firmware
Vendor
Zyxel
Product
Wac6103d-i
Zyxel
Wac6103d-i
Vendor
Zyxel
Product
Wac6103d-i Firmware
Zyxel
Wac6103d-i Firmware
Vendor
Zyxel
Product
Wax300h
Zyxel
Wax300h
Vendor
Zyxel
Product
Wax300h Firmware
Zyxel
Wax300h Firmware
Vendor
Zyxel
Product
Wax510d
Zyxel
Wax510d
Vendor
Zyxel
Product
Wax510d Firmware
Zyxel
Wax510d Firmware
Vendor
Zyxel
Product
Wax610d
Zyxel
Wax610d
Vendor
Zyxel
Product
Wax610d Firmware
Zyxel
Wax610d Firmware
Vendor
Zyxel
Product
Wax620d-6e
Zyxel
Wax620d-6e
Vendor
Zyxel
Product
Wax620d-6e Firmware
Zyxel
Wax620d-6e Firmware
Vendor
Zyxel
Product
Wax630s
Zyxel
Wax630s
Vendor
Zyxel
Product
Wax630s Firmware
Zyxel
Wax630s Firmware
Vendor
Zyxel
Product
Wax640s-6e
Zyxel
Wax640s-6e
Vendor
Zyxel
Product
Wax640s-6e Firmware
Zyxel
Wax640s-6e Firmware
Vendor
Zyxel
Product
Wax650s
Zyxel
Wax650s
Vendor
Zyxel
Product
Wax650s Firmware
Zyxel
Wax650s Firmware
Vendor
Zyxel
Product
Wax655e
Zyxel
Wax655e
Vendor
Zyxel
Product
Wax655e Firmware
Zyxel
Wax655e Firmware
Vendor
Zyxel
Product
Wbe530
Zyxel
Wbe530
Vendor
Zyxel
Product
Wbe530 Firmware
Zyxel
Wbe530 Firmware
Vendor
Zyxel
Product
Wbe660s
Zyxel
Wbe660s
Vendor
Zyxel
Product
Wbe660s Firmware
Zyxel
Wbe660s Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
