CVE-2025-6265 patches/firmware availability

Options
mMontana
mMontana Posts: 1,432  Guru Member
Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers 1000 Comments
edited July 15 in Wireless

Hey, thanks for the heads up

twice!

https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-path-traversal-vulnerability-in-aps-07-15-2025

about the vulnerability and the patch availability…

Which at time of writing have no links into advisory bullettin, not available on the download page… and no ETA date/time.

Am I missing something?

All Replies

  • PeterUK
    PeterUK Posts: 3,893  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    The need to wait?

  • mMontana
    mMontana Posts: 1,432  Guru Member
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers 1000 Comments

    You're probably correct, @peteruk; however

    I'm not happy that there's the vulnerability, but I am grateful that there will be a correction from Zyxel.

    According to Mitre

    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6265

    CVE has been reserver roughly 25 days ago, and it's classified "not that low" in severity scale (7.2). EPSS (exploitability) is 0,08% at this date.
    I'm glad that the correction has been declared then will be release. So why do not share an estimated ETA?

    This security advisory (in my opinion) lacks in delivering information on when the actual resolution could be appled to products. A better realized advisory with more informations would make this topic useless and redundant.

  • PeterUK
    PeterUK Posts: 3,893  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    No one is happy but vulnerability were in the AP from when they had them to which we would not know unless told so would you of like Zyxel to say nothing till all firmware patches are available?

  • mMontana
    mMontana Posts: 1,432  Guru Member
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers 1000 Comments

    An ETA of firmware availability could be useful.

  • AndersW
    AndersW Posts: 4  Freshman Member
    Zyxel Certified Network Administrator - Nebula First Comment First Anniversary

    Nebula Control Center Upgrade Notification

    Dear Nebula Admins,

    From Jul.28, 2025 0:20 AM to Jul.28, 2025 1:00 AM UTC+0, we will be upgrading Nebula Control Center (NCC) to release 19.10 by adding some improvements and new features.

    Also, with this new update, we will have Latest firmware released for devices including

    • AP: WAC500H (V6.70P7);NWA50AX, NWA50AX PRO, NWA55AXE, NWA90AX, NWA90AX PRO; NWA110AX, NWA210AX, WAX300H, WAX510D, WAX610D, WAX630S, WAX650S; NWA220AX-6E, WAX620D-6E, WAX640S-6E and WAX655E (V7.10P3);NWA50BE, NWA50BE PRO, NWA90BE, NWA90BE PRO, NWA110BE, NWA130BE, NWA210BE, WBE510D, WBE530, WBE630S and WBE660S (V7.20)
    • Switch: XGS1930 series & XGS2220 series (V5.00); XMG2230 series (V2.00)
    • Firewall: USG FLEX H series (V1.35)
    • Security Router: USG LITE 60AX (V2.20)
    • Mobile Router: FWA505 (V1.19); FWA515 (V1.5)

    that enables them to support these NCC enhancements. If you have these devices and your firmware type setting in NCC firmware management configured with Latest option, please follow the instructions of the firmware notification emails sent to you after the new update has been done.

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,529  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @mMontana Thanks for bring this to our attention.

    The fixed firmware file is available from this forum post:

    Additionally, the official firmware will be available at the end of July on our officail website and Nebula Control Center.

    Zyxel Melen