PT-2026-7623 · Shenzhen Zhiboton Electronics · Zbt We2001
Published
2026-02-11
·
Updated
2026-02-17
·
CVE-2025-65128
CVSS v3.1
8.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Shenzhen Zhibotong Electronics ZBT WE2001 version 23.09.27
Description
A flaw exists in the web management API components that allows unauthenticated attackers on the local network to modify router and network configurations. Attackers can change configuration data, including SSID, Wi-Fi credentials, and administrative passwords, without authentication by invoking operations ending with
* nocommit and providing the expected parameters for the invoked function.Recommendations
Apply updates to address the missing authentication mechanism in the web management API components. As a temporary workaround, restrict network access to the web management API to trusted users only.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zbt We2001