CVE-2025-64075

Critical severity, CVSS 10.0. EPSS: 0.8% chance of exploitation in the next 30 days.

A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass authentication and perform administrative actions by supplying a crafted session cookie value.

Published 2026-02-11. Last modified 2026-06-17.