VYPR

ZBT WE2001

by Shenzhen Zhibotong Electronics

CVEs (4)

  • CVE-2025-64075CriFeb 11, 2026
    risk 0.65cvss 10.0epss 0.01

    A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass authentication and perform administrative actions by supplying a crafted session cookie value.

  • CVE-2025-65128HigFeb 11, 2026
    risk 0.53cvss 8.1epss 0.00

    A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unauthenticated attackers on the local network to modify router and network configurations. By invoking operations whose names end with "*_nocommit" and supplying the parameters expected by the invoked function, an attacker can change configuration data, including SSID, Wi-Fi credentials, and administrative passwords, without authentication or an existing session.

  • CVE-2025-65127MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote unauthenticated attackers to access administrative information-retrieval functions intended for authenticated users. By invoking "get_*" operations, attackers can obtain device configuration data, including plaintext credentials, without authentication or an existing session.

  • CVE-2025-64074MedFeb 11, 2026
    risk 0.34cvss 5.3epss 0.00

    A path-traversal vulnerability in the logout functionality of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to delete arbitrary files on the host by supplying a crafted session cookie value.