CVE-2026-25084Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • Peaked 3d ago at 4 mentions (2026-02-11); latest day: 2
  • 8 total mentions across 4 days

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-02-11: 4Mentions · 2026-02-12: 1Mentions · 2026-02-13: 1Mentions · 2026-02-16: 2Patch / Workaround · 2026-02-11: 1Patch / Workaround · 2026-02-16: 1Technical Details · 2026-02-11: 4Technical Details · 2026-02-12: 1Technical Details · 2026-02-13: 1Technical Details · 2026-02-16: 202-1102-1202-1302-16
Signal classification2 categories
Disclosure
675.0%
Patch
225.0%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-02-114
Disclosure3Patch1
2026-02-121
Disclosure1
2026-02-131
Disclosure1
2026-02-162
Disclosure1Patch1
Full discourse8 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    CISA warns of critical ZLAN5143D flaws CVE-2026-25084 & CVE-2026-24789. Attackers can bypass login & reset passwords. Isolate devices now. #ZLAN #CISA #ICS #OTSecurity #CyberSecurity #CVE202625084 #IndustrialIoT https://securityonline.info/critical-zlan5143d-flaws-cvss-9-8-allow-total-takeover-no-patch-available/

    Post summary

    CISA warns about CVE-2026-25084 and CVE-2026-24789 in ZLAN5143D, highlighting authentication bypass and password reset weaknesses, with no patch currently available.

    00020354
    10.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25084 Authentication Bypass Vulnerability in ZLAN5143D Internal URL Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25084

    Post summary

    A new CVE, CVE‑2026‑25084, is announced describing an authentication bypass in ZLAN5143D internal URLs, with a link to more details but no PoC, exploit, patch, or active exploitation information.

    0002038
    4.0K followersView on X
  • NerdieNews@NewsNerdie
    Disclosure

    Today's Top Cybersecurity News – February 13, 2026 1. Critical WPvivid Backup Flaw (CVSS 9.8) Exposes 800K WordPress Sites A critical vulnerability (CVE-2026-1357) in the WPvivid Backup plugin affects over 800,000 WordPress sites, potentially exposing sensitive backup data. This flaw poses a significant risk of data compromise and site integrity loss if exploited. Sources: Bleepingcomputer, Cvefeed, Darkreading, Feedburner, Gbhackers, Infosecurity-Magazine, Intel471, Malwarebytes, Mandiant, Proofpoint, Securityweek, Therecord https://securityonline.info/null-byte-nightmare-critical-wpvivid-backup-flaw-cvss-9-8-exposes-800k-wordpress-sites/ 2. Critical SandboxJS Vulnerability (CVE-2026-25881) Enables Host Takeover A critical flaw in SandboxJS allows attackers to escape the sandbox environment and execute malicious code on the host system. This vulnerability poses a severe risk to applications relying on SandboxJS for secure JavaScript execution. Sources: Cvefeed, Microsoft https://securityonline.info/sandbox-breakout-critical-sandboxjs-flaw-cve-2026-25881-allows-host-takeover/ 3. Multiple High and Critical Vulnerabilities Including Authentication Bypass, Buffer Overflows, and Path Traversal A series of critical and high-severity vulnerabilities have been disclosed affecting various software products including PRO-7070, OwnCloud, SpotAuditor, and others. These vulnerabilities enable attackers to bypass authentication, execute arbitrary code via buffer overflows and stack overflows, perform path traversal to access sensitive files, and disclose usernames, posing significant risks to affected systems. Immediate patching and mitigation are recommended to prevent unauthorized access and potential system compromise. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2019-25335 4. Multiple Critical Vulnerabilities in CIPPlanner CIPAce Allow Privilege Escalation and Arbitrary File Access CIPPlanner CIPAce versions before 9.17 contain multiple severe vulnerabilities including account privilege escalation, unauthorized file download, and arbitrary file upload of executable files. These flaws enable low-privileged authenticated users to escalate privileges, access unauthorized files, and potentially execute malicious code, posing significant security risks. Sources: Cvefeed, Feedburner, Securityaffairs https://cvefeed.io/vuln/detail/CVE-2024-50619 5. Critical Authentication Bypass Vulnerabilities Found in ZLAN5143D Devices Two critical vulnerabilities (CVE-2026-25084 and CVE-2026-24789) affect ZLAN5143D devices, allowing attackers to bypass authentication and remotely change device passwords via unprotected internal URLs and API endpoints. These flaws expose devices to unauthorized access and control, posing significant security risks. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-25084 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The piece announces several newly disclosed critical vulnerabilities across multiple products, detailing CVE identifiers, severity scores, and high-level impact, but does not provide PoC, exploit code, or evidence of active exploitation.

    0001056
    54 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25084 Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs. https://www.cve.org/CVERecord?id=CVE-2026-25084

    Post summary

    The post discloses an authentication bypass vulnerability (CVE‑2026‑25084) in ZLAN5143D, noting that direct access to internal URLs can be exploited, but no PoC, exploit code, patch, or active exploitation claim is provided.

    00010192
    56.5K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 CISA Warns: Critical ZLAN5143D ICS Bugs Allow Full Device Takeover (CVSS 9.8) CISA advisory ICSA-26-041-02 flags two critical ZLAN5143D serial-to-Ethernet flaws—CVE-2026-25084 (missing auth) and CVE-2026-24789 (auth bypass/password reset)—that enable unauthenticated remote admin control on firmware v1.600. This matters because these devices often bridge IT/OT in manufacturing, so compromise can become a lateral-movement pivot into control networks; isolate from the internet, segment OT, and patch/monitor immediately. 🎯 Target: Global/Manufacturing & ICS/OT #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://cyberpress.org/zlan-ics-flaws/

    Post summary

    CISA alerts about two critical ZLAN5143D flaws that allow remote takeover; immediate isolation and patching are advised.

    0000030
    176 followersView on X
  • Säkerhetsbloggen@Sakerhetsblogg
    Patch

    CVE-2026-25084 möjliggör autentiseringsbypass på ZLAN5143D, vilket riskerar känslig information. Öka säkerheten genom att uppdatera till senaste version och implementera strikt autentisering. #säkerhet #cybersäkerhet #CVE

    Post summary

    CVE-2026-25084 allows an authentication bypass on ZLAN5143D devices, risking sensitive information; users are advised to upgrade to the latest firmware and enforce strict authentication to mitigate the threat.

    0000031
    7 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-25084: CRITICAL] Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs.#cve,CVE-2026-25084,#cybersecurity https://cvefind.com/CVE-2026-25084

    Post summary

    The tweet announces CVE‑2026‑25084, a critical authentication bypass in ZLAN5143D via internal URLs, without mentioning a PoC, exploit code, active attacks, or a patch.

    0000067
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25084 - Critical Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs. https://www.thehackerwire.com/vulnerability/CVE-2026-25084/ https://t.co/j2cuXJEX7b

    Post summary

    The tweet announces CVE-2026-25084 as a critical authentication bypass for ZLAN5143D, noting that internal URLs can be accessed to bypass authentication; no PoC, exploit tool, active exploitation, or patch is discussed.

    0000062
    112 followersView on X

Explore more