[Vulnerability Hotfix] CVE-2025-6265 Path Traversal Vulnerability



Firmware versions 6.70 Patch 7, 7.10 Patch 3, and 7.20 Patch 1 address the CVE-2025-6265 potential path traversal vulnerability.
If you are using Standalone mode or Controller-Managed mode, you can download the corresponding AP firmware version from the link below:
AP Model | Patch Availability |
---|---|
NWA50AX | |
NWA50AX PRO | |
NWA55AXE | |
NWA90AX | |
NWA90AX PRO | |
NWA110AX | |
NWA130BE | |
NWA210AX | |
NWA220AX-6E | |
NWA1123AC PRO | |
WAC500H | |
WAC5302D-Sv2 | |
WAC6103D-I | |
WAX300H | |
WAX510D | |
WAX610D | |
WAX620D-6E | |
WAX630S | |
WAX640S-6E | |
WAX650S | |
WAX655E | |
WBE530 | |
WBE660S |
However, if you are a Nebula-managed user, please note that manually upgrading your AP to the above-mentioned firmware versions may cause issues.
*As the Nebula server has not yet been updated to support the new feature configurations, any modifications to WLAN-related settings may not be successfully propagated to the access point.
Therefore, if you urgently need to apply the vulnerability fix, please avoid modifying any WLAN-related settings after upgrading the AP firmware.
The Nebula is scheduled to be updated on July 28, 2025, to support the corresponding firmware versions.
Once both the AP firmware and the Nebula server are aligned, you will be able to modify WLAN-related settings as usual.
Categories
- All Categories
- 435 Beta Program
- 2.7K Nebula
- 183 Nebula Ideas
- 120 Nebula Status and Incidents
- 6.2K Security
- 440 USG FLEX H Series
- 299 Security Ideas
- 1.6K Switch
- 80 Switch Ideas
- 1.2K Wireless
- 44 Wireless Ideas
- 6.7K Consumer Product
- 276 Service & License
- 433 News and Release
- 88 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 84 About Community
- 91 Security Highlight