Missing Authentication Mechanism in Zhibotong Electronics' Router Management API
CVE-2025-65128

8.1HIGH

Key Information:

Vendor
CVE Published:
11 February 2026

What is CVE-2025-65128?

The web management API in the ZBT WE2001 model from Shenzhen Zhibotong Electronics contains a significant security flaw due to a lack of authentication. This allows attackers on the local network to exploit the API's functionality. By using specific operation names with parameters that the system expects, unauthorized individuals can alter critical configuration settings, such as SSID and Wi-Fi credentials, as well as administrative passwords. This vulnerability poses a serious risk to the network's integrity and security, making it essential for users to be aware and take preventive measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.