{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T21:47:01.759","vulnerabilities":[{"cve":{"id":"CVE-2025-3577","sourceIdentifier":"security@zyxel.com.tw","published":"2025-04-22T03:15:21.637","lastModified":"2026-06-17T09:20:13.887","vulnStatus":"Analyzed","cveTags":[{"sourceIdentifier":"security@zyxel.com.tw","tags":["unsupported-when-assigned"]}],"descriptions":[{"lang":"en","value":"**UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B firmware version 2.00(AAJC.16)C0 could allow an authenticated attacker with administrator privileges to access restricted directories by sending a crafted HTTP request to an affected device."},{"lang":"es","value":"**NO COMPATIBLE CUANDO SE ASIGNÓ** Una vulnerabilidad de path traversal en la interfaz de administración web de la versión de firmware 2.00(AAJC.16)C0 del Zyxel AMG1302-T10B podría permitir que un atacante autenticado con privilegios de administrador acceda a directorios restringidos mediante el envío de una solicitud HTTP manipulada a un dispositivo afectado."}],"affected":[{"source":"security@zyxel.com.tw","affectedData":[{"vendor":"Zyxel","product":"AMG1302-T10B firmware","defaultStatus":"unaffected","versions":[{"version":"2.00(AAJC.16)C0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@zyxel.com.tw","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-22T13:28:07.029291Z","id":"CVE-2025-3577","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@zyxel.com.tw","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:amg1302-t10b_firmware:2.00\\(aajc.16\\)c0:*:*:*:*:*:*:*","matchCriteriaId":"824D36A3-0CB6-4BCA-939E-BECE269BC2D1"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:amg1302-t10b:-:*:*:*:*:*:*:*","matchCriteriaId":"879BFC87-77C5-4762-8E6B-D3623476FC95"}]}]}],"references":[{"url":"https://github.com/Jiangxiazhe/IOT_Vulnerability/blob/main/README.md","source":"security@zyxel.com.tw","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.zyxel.com/service-provider/global/en/security-advisories/end-of-life","source":"security@zyxel.com.tw","tags":["Product"]},{"url":"https://github.com/Jiangxiazhe/IOT_Vulnerability/blob/main/README.md","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]}]}}]}