PT-2025-17479 · Unknown · Postgresql+1

Alessandro Sgreccia

+1

·

Published

2025-04-21

·

Updated

2025-10-30

·

CVE-2025-1731

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions USG FLEX H series uOS firmware versions from V1.20 through V1.31
Description An incorrect permission assignment vulnerability in the PostgreSQL commands could allow an authenticated local attacker with low privileges to gain access to the Linux shell and escalate their privileges by crafting malicious scripts or modifying system configurations with administrator-level access through a stolen token. Modifying the system configuration is only possible if the administrator has not logged out and the token remains valid.
Recommendations For USG FLEX H series uOS firmware versions from V1.20 through V1.31, consider disabling the PostgreSQL command processing as a temporary workaround until a patch is available. Restrict access to the Linux shell to minimize the risk of exploitation. Avoid using stolen tokens for administrator-level access until the issue is resolved.

Exploit

Fix

LPE

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2025-12737
CVE-2025-1731

Affected Products

Postgresql
Usg Flex H Series