Session Validation Flaw in Shenzhen Zhibotong Electronics ZBT WE2001 Web API
CVE-2025-65127
6.5MEDIUM
Key Information:
- Status
- Vendor
- CVE Published:
- 11 February 2026
What is CVE-2025-65127?
A security flaw in the web API of the Shenzhen Zhibotong Electronics ZBT WE2001 allows remote attackers to leverage inadequate session validation. This vulnerability enables unauthorized users to access critical administrative functions without the need for authentication, as they can exploit the 'get_*' operations to retrieve sensitive device configuration information, including plaintext credentials. This issue poses significant risks to device security and integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
