Hi, Please find attached a security advisory that describes some vulnerabilities we discovered in the Zyxel uOS Linux-based operating system. * Title: Local privilege escalation via Zyxel fermion-wrapper * Product: USG FLEX H Series * OS: Zyxel uOS V1.31 (and potentially earlier versions) * Author: Marco Ivaldi <marco.ivaldi () hnsecurity it> * Date: 2025-04-23 * CVE ID: CVE-2025-1731 (see discussion in "5 - Remediation" below) * Severity: High - 7.8 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CWE ID: CWE-61 - https://cwe.mitre.org/data/definitions/61.html * HN Security URLs: * https://github.com/hnsecurity/vulns/blob/main/HNS-2025-10-zyxel-fermion.txt * https://github.com/0xdea/exploits/blob/master/zyxel/raptor_fermion * https://security.humanativaspa.it/local-privilege-escalation-on-zyxel-usg-flex-h-series-cve-2025-1731 * Vendor URLs: * https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-incorrect-permission-assignment-and-improper-privilege-management-vulnerabilities-in-usg-flex-h-series-firewalls-04-22-2025 * https://community.zyxel.com/en/discussion/28988/usg-flex-h-series-v1-32patch-0-firmware-release For additional information, please refer to our vulnerability writeup: https://security.humanativaspa.it/local-privilege-escalation-on-zyxel-usg-flex-h-series-cve-2025-1731/ Regards, -- Marco Ivaldi https://0xdeadbeef.info/ "When cryptography is outlawed, bayl bhgynjf jvyy unir cevinpl."
Attachment:
HNS-2025-10-zyxel-fermion.txt
Description:
_______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/