CVE-2025-65127 – ZBT WE2001 Session Validation Bypass

CVE ID : CVE-2025-65127

Published : Feb. 11, 2026, 5:16 p.m. | 1 hour, 8 minutes ago

Description : A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote unauthenticated attackers to access administrative information-retrieval functions intended for authenticated users. By invoking “get_*” operations, attackers can obtain device configuration data, including plaintext credentials, without authentication or an existing session.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more… 

نوشته های مشابه