An incorrect permission assignment vulnerability in the PostgreSQL commands of the USG FLEX H series uOS firmware versions from V1.20 through V1.31 could allow an authenticated local attacker with low privileges to gain access to the Linux shell and escalate their privileges by crafting malicious scripts or modifying system configurations with administrator-level access through a stolen token. Modifying the system configuration is only possible if the administrator has not logged out and the token remains valid.
History

Thu, 24 Apr 2025 06:45:00 +0000

Type Values Removed Values Added
References

Tue, 22 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Apr 2025 02:30:00 +0000

Type Values Removed Values Added
Description An incorrect permission assignment vulnerability in the PostgreSQL commands of the USG FLEX H series uOS firmware versions from V1.20 through V1.31 could allow an authenticated local attacker with low privileges to gain access to the Linux shell and escalate their privileges by crafting malicious scripts or modifying system configurations with administrator-level access through a stolen token. Modifying the system configuration is only possible if the administrator has not logged out and the token remains valid.
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published: 2025-04-22T01:52:04.064Z

Updated: 2025-04-24T06:04:04.291Z

Reserved: 2025-02-27T03:13:40.559Z

Link: CVE-2025-1731

cve-icon Vulnrichment

Updated: 2025-04-24T06:04:04.291Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-22T03:15:21.177

Modified: 2025-04-24T06:15:45.497

Link: CVE-2025-1731

cve-icon Redhat

No data.