CVE-2025-65128Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unauthenticated attackers on the local network to modify router and network configurations. By invoking operations whose names end with "*_nocommit" and supplying the parameters expected by the invoked function, an attacker can change configuration data, including SSID, Wi-Fi credentials, and administrative passwords, without authentication or an existing session.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-11); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-11: 1Mentions · 2026-02-12: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-12: 102-1102-12
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-65128 Unauthenticated Configuration Modification in ZBT WE2001 Web Management API https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-65128

    Post summary

    CVE-2025-65128 is a newly disclosed unauthenticated configuration modification vulnerability in the ZBT WE2001 Web Management API. No exploit details, patch information, or active exploitation evidence are provided.

    0001039
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-65128 A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unauthenticated attackers on the … https://www.cve.org/CVERecord?id=CVE-2025-65128

    Post summary

    CVE-2025-65128 describes an unauthenticated access flaw in the web management API of Shenzhen Zhibotong Electronics ZBT WE2001 due to a missing authentication check.

    00000343
    56.5K followersView on X

Explore more