CVE-2025-8078PoC(zyxel / atp100)

HIGHCVSS 7.2 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch zyxel atp100 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 through V5.40, USG FLEX 50(W) series firmware versions from V4.16 through V5.40, and USG20(W)-VPN series firmware versions from V4.16 through V5.40 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on the affected device by passing a crafted string as an argument to a CLI command.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • atp100
  • atp100w
  • atp200
  • atp500

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-02-18); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
atp100atp100watp200atp500atp700atp800usg_20w-vpnusg_flex_100usg_flex_100axusg_flex_100w

1 version affected across 17 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-18: 1Mentions · 2026-09-22: 1PoC Mentioned / Linked · 2026-02-18: 1Active Exploitation · 2026-09-22: 1Patch / Workaround · 2026-09-22: 1Technical Details · 2026-02-18: 1Technical Details · 2026-09-22: 102-1809-22
Signal classification2 categories
PoC
150.0%
Active Exploitation
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-181
PoC1
2026-09-221
Active Exploitation1
Full discourse2 posts
  • reverseame@reverseame
    PoC

    CVE-2025-8078: Remote Code Execution via CLI Command Injection #CVE20258078 #RemoteCodeExecution #CommandInjection #ZYXEL #Exploit https://rainpwn.blog/blog/cve-2025-8078/

    Post summary

    A blog post link about CVE‑2025‑8078 is provided, highlighting a remote code execution vulnerability via CLI command injection in ZYXEL devices, but no active exploitation, patch, or detailed exploit tool is mentioned.

    04054861
    21.6K followersView on X
  • MadeItHappen@MadeItHappenX
    Active Exploitation

    Kids, that little Zyxel GS1900 under the desk? CISA put CVE-2025-8078 on the KEV list yesterday. Stack overflow in the web CGI. No login needed if you're already on the LAN. GreyNoise saw nearly a thousand of them drained across 48 countries. Patch the firmware. Those switches are not furniture. Mmkay. https://www.cisa.gov/news-events/alerts/2025/08/13/cisa-adds-three-known-exploited-vulnerabilities-catalog

    Post summary

    The text reports that CVE-2025-8078 is on CISA's Known Exploited Vulnerabilities list, with evidence of active exploitation observed by GreyNoise, and advises patching the firmware.

    0000076
    254 followersView on X
CPE platform detail17 entries

17 of 17 entries

PartVendorProductVersionTarget SWTarget HW
HWzyxelatp100---
HWzyxelatp100w---
HWzyxelatp200---
HWzyxelatp500---
HWzyxelatp700---
HWzyxelatp800---
HWzyxelusg_20w-vpn---
HWzyxelusg_flex_100---
HWzyxelusg_flex_100ax---
HWzyxelusg_flex_100w---
HWzyxelusg_flex_200---
HWzyxelusg_flex_50---
HWzyxelusg_flex_500---
HWzyxelusg_flex_50ax---
HWzyxelusg_flex_50w---
HWzyxelusg_flex_700---
OSzyxelzld---

Explore more