CVE-2025-65128 Details
Description
A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unauthenticated attackers on the local network to modify router and network configurations. By invoking operations whose names end with "*_nocommit" and supplying the parameters expected by the invoked function, an attacker can change configuration data, including SSID, Wi-Fi credentials, and administrative passwords, without authentication or an existing session.
A vulnerability exists in the web management API of the Shenzhen Zhibotong Electronics ZBT WE2001 router, specifically in version 23.09.27. The issue arises from a missing authentication mechanism, allowing unauthenticated attackers on the local network to alter router and network settings. Exploitation involves invoking specific operations that end with '*_nocommit' and providing the required parameters, enabling attackers to change various configuration details such as the SSID, Wi-Fi passwords, and administrative credentials, all without the need for authentication or an active session.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 11, 2026CISA-ADP
Assessed Feb 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://neutsec.io/advisories/cve-2025-65128/ | [email protected] | Advisory |
| https://www.zbtwifi.com/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Shenzhen Zhibotong Electronics ZBT WE2001 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 17, 2026 | CVE Modified | CISA-ADP |
| Feb 12, 2026 | CVE Modified | CISA-ADP |
| Feb 11, 2026 | New CVE Received | [email protected] |
Volerion