CVE-2025-6265: Zyxel NWA110AX Firmware

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

A path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware version 7.10(ACGE.2) and earlier could allow an authenticated attacker with administrator privileges to access specific directories and delete files, such as the configuration file, on the affected device.

Affected products

  • Zyxel NWA110AX Firmware: up to and including 7.10\(abtg.1\)
  • Zyxel NWA1123AC Pro Firmware: up to and including 6.28\(abhd.3\)
  • Zyxel NWA130BE Firmware: up to and including 7.10\(acil.2\)
  • Zyxel NWA210AX Firmware: up to and including 7.10\(abtd.1\)
  • Zyxel NWA220AX-6e Firmware: up to and including 7.10\(acco.1\)
  • Zyxel NWA50AX Firmware: up to and including 7.10\(abyw.1\)
  • Zyxel NWA50AX Pro Firmware: up to and including 7.10\(acge.2\)
  • Zyxel NWA55AXE Firmware: up to and including 7.10\(abzl.1\)
  • Zyxel NWA90AX Firmware: up to and including 7.10\(accv.1\)
  • Zyxel NWA90AX Pro Firmware: up to and including 7.10\(acgf.2\)
  • Zyxel WAC500H Firmware: up to and including 6.70\(abwa.6\)
  • Zyxel WAC5302D-SV2 Firmware: up to and including 6.25\(abvz.9\)
  • Zyxel WAC6103D-I Firmware: up to and including 6.28\(aaxh.3\)
  • Zyxel WAX300H Firmware: up to and including 7.10\(achf.1\)
  • Zyxel WAX510D Firmware: up to and including 7.10\(abtf.1\)
  • Zyxel WAX610D Firmware: up to and including 7.10\(abte.1\)
  • Zyxel WAX620D-6e Firmware: up to and including 7.10\(accn.1\)
  • Zyxel WAX630S Firmware: up to and including 7.10\(abzd.1\)
  • Zyxel WAX640S-6e Firmware: up to and including 7.10\(accm.1\)
  • Zyxel WAX650S Firmware: up to and including 7.10\(abrm.1\)
  • Zyxel WAX655E Firmware: up to and including 7.10\(acdo.1\)
  • Zyxel WBE530 Firmware: up to and including 7.10\(acle.2\)
  • Zyxel WBE660S Firmware: up to and including 7.10\(acgg.2\)

Published 2025-07-15. Last modified 2026-06-17.