Missing Authentication Mechanism in Zhibotong Electronics' Router Management API
CVE-2025-65128
Key Information:
- Status
- Vendor
- CVE Published:
- 11 February 2026
What is CVE-2025-65128?
The web management API in the ZBT WE2001 model from Shenzhen Zhibotong Electronics contains a significant security flaw due to a lack of authentication. This allows attackers on the local network to exploit the API's functionality. By using specific operation names with parameters that the system expects, unauthorized individuals can alter critical configuration settings, such as SSID and Wi-Fi credentials, as well as administrative passwords. This vulnerability poses a serious risk to the network's integrity and security, making it essential for users to be aware and take preventive measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
