[Vulnerability Hotfix] CVE-2025-6265 Path Traversal Vulnerability



Firmware versions 6.70 Patch 7, 7.10 Patch 3, and 7.20 Patch 1 address the CVE-2025-6265 potential path traversal vulnerability.
If you are using Standalone mode or Controller-Managed mode, you can download the corresponding AP firmware version from the link below:
AP Model | Patch Availability |
---|---|
NWA50AX | |
NWA50AX PRO | |
NWA55AXE | |
NWA90AX | |
NWA90AX PRO | |
NWA110AX | |
NWA130BE | |
NWA210AX | |
NWA220AX-6E | |
NWA1123AC PRO | |
WAC500H | |
WAC5302D-Sv2 | |
WAC6103D-I | |
WAX300H | |
WAX510D | |
WAX610D | |
WAX620D-6E | |
WAX630S | |
WAX640S-6E | |
WAX650S | |
WAX655E | |
WBE530 | |
WBE660S |
However, if you are a Nebula-managed user, please note that manually upgrading your AP to the above-mentioned firmware versions may cause issues.
*As the Nebula server has not yet been updated to support the new feature configurations, any modifications to WLAN-related settings may not be successfully propagated to the access point.
Therefore, if you urgently need to apply the vulnerability fix, please avoid modifying any WLAN-related settings after upgrading the AP firmware.
The Nebula is scheduled to be updated on July 28, 2025, to support the corresponding firmware versions.
Once both the AP firmware and the Nebula server are aligned, you will be able to modify WLAN-related settings as usual.
Categories
- All Categories
- 435 Beta Program
- 2.7K Nebula
- 176 Nebula Ideas
- 118 Nebula Status and Incidents
- 6.1K Security
- 428 USG FLEX H Series
- 298 Security Ideas
- 1.6K Switch
- 78 Switch Ideas
- 1.2K Wireless
- 44 Wireless Ideas
- 6.7K Consumer Product
- 274 Service & License
- 419 News and Release
- 88 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 89 Security Highlight