CVE-2025-1731
An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware versions from V1.20 through V1.31 could allow an authenticated local attacker with low privileges to gain access to the Linux shell and escalate their privileges by crafting malicious scripts or modifying system configurations with administrator-level access through a stolen token. Modifying the system configuration is only possible if the administrator has not logged out and the token remains valid.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.94%
- Percentil entre todas las CVEs puntuadas: 60
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation95 % - Impacto principal
T1548Abuse Elevation Control Mechanismprivilege escalation90 % - Impacto secundario
T1059.004Unix Shellexecution85 % - Impacto secundario
T1098.002Additional Email Delegate Permissionspersistence · privilege escalation75 %
Vulnerabilidad de permisos incorrectos (CWE-732) en entorno local con acceso de usuario de bajos privilegios que permite escalada a nivel de administrador. AV:L, PR:L, UI:N confirma T1068. Impactos: acceso de shell Linux (T1059.004), manipulación de tokens/sesiones (T1098.002), y acceso elevado (T15
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-732
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-1731",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-1731",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-05-02T03:55:18.303921Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@zyxel.com.tw",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "security@zyxel.com.tw",
"affectedData": [
{
"vendor": "Zyxel",
"product": "USG FLEX H series uOS firmware",
"versions": [
{
"status": "affected",
"version": "from V1.20 through V1.31"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-04-22T03:15:21.177",
"references": [
{
"url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-incorrect-permission-assignment-and-improper-privilege-management-vulnerabilities-in-usg-flex-h-series-firewalls-04-22-2025",
"tags": [
"Vendor Advisory"
],
"source": "security@zyxel.com.tw"
},
{
"url": "http://seclists.org/fulldisclosure/2025/Apr/27",
"tags": [
"Mailing List"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@zyxel.com.tw",
"description": [
{
"lang": "en",
"value": "CWE-732"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware versions from V1.20 through V1.31 could allow an authenticated local attacker with low privileges to gain access to the Linux shell and escalate their privileges by crafting malicious scripts or modifying system configurations with administrator-level access through a stolen token. Modifying the system configuration is only possible if the administrator has not logged out and the token remains valid."
},
{
"lang": "es",
"value": "Una vulnerabilidad de asignación incorrecta de permisos en los comandos PostgreSQL de las versiones de firmware uOS de la serie USG FLEX H, de la V1.20 a la V1.31, podría permitir que un atacante local autenticado con privilegios bajos acceda al shell de Linux y aumente sus privilegios mediante la creación de scripts maliciosos o la modificación de la configuración del sistema con acceso de administrador mediante un token robado. La modificación de la configuración del sistema solo es posible si el administrador no ha cerrado sesión y el token sigue siendo válido."
}
],
"lastModified": "2026-06-17T08:39:40.800",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:uos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E4CCD46D-8AAF-4ABC-B9CF-AE1ED1F45D48",
"versionEndExcluding": "1.32",
"versionStartIncluding": "1.20"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg_flex_100h:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "ED28D5ED-B21A-4CD6-947E-9C21EA801B7D"
},
{
"criteria": "cpe:2.3:h:zyxel:usg_flex_100hp:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "ACCFC4B1-37DD-4BF7-86A9-5F0A9A2C1D07"
},
{
"criteria": "cpe:2.3:h:zyxel:usg_flex_200h:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "09D15ECD-4942-407A-A62E-9785568C6B78"
},
{
"criteria": "cpe:2.3:h:zyxel:usg_flex_200hp:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FD7E9028-1ECB-4D88-84D8-CFC589B429AE"
},
{
"criteria": "cpe:2.3:h:zyxel:usg_flex_500h:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DE57BCA4-8631-460A-BFE3-BB765E5D009F"
},
{
"criteria": "cpe:2.3:h:zyxel:usg_flex_50h:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "875DC0B8-0189-4952-9FD8-00970F4C72F5"
},
{
"criteria": "cpe:2.3:h:zyxel:usg_flex_50hp:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F3697878-4927-4381-BA26-3FD9A08D7661"
},
{
"criteria": "cpe:2.3:h:zyxel:usg_flex_700h:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8832743A-99FA-417E-BCE1-4BF7D4CEF9BE"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security@zyxel.com.tw"
}