HNS-2025-10 – HN Security Advisory – Local privilege escalation in Zyxel uOS – Full Disclosure

Posted by Marco Ivaldi on Apr 23
Hi,
Please find attached a security advisory that describes some
vulnerabilities we discovered in the Zyxel uOS Linux-based operating
system.
* Title: Local privilege escalation via Zyxel fermion-wrapper
* Product: USG FLEX H Series
* OS: Zyxel uOS V1.31 (and potentially earlier versions)
* Author: Marco Ivaldi <marco.ivaldi () hnsecurity it>
* Date: 2025-04-23
* CVE ID: CVE-2025-1731 (see discussion in “5 – Remediation” below)…
– Read More – Full Disclosure