Zyxel has disclosed multiple security vulnerabilities affecting several of its firewall product lines, including the ATP, USG FLEX, USG FLEX 50(W), and USG20(W)-VPN series. One of the critical vulnerabilities, tracked as CVE-2025-9133, is a missing authorization flaw present in ATP series firmware versions from V4.32 through V5.40, USG FLEX series from V4.50 through V5.40, USG FLEX 50(W) from V4.16 through V5.40, and USG20(W)-VPN from V4.16 through V5.40. This vulnerability allows a semi-authenticated attacker—someone who has completed only the first stage of the two-factor authentication (2FA) process—to view and download the system configuration from an affected device. The ability to access configuration files could expose sensitive information, including network settings and potentially credentials, increasing the risk of further compromise. The vulnerability is remotely exploitable, making it a significant concern for organizations using these devices in perimeter security roles. In addition to the missing authorization issue, Zyxel's advisory also addresses a post-authentication command injection vulnerability in the same product lines, further elevating the risk profile. The Canadian Centre for Cyber Security has issued an alert urging users and administrators to review Zyxel's advisories and apply the necessary firmware updates to mitigate these risks. The vulnerabilities impact a wide range of firmware versions, indicating that many deployed devices may be at risk if not promptly updated. Zyxel has published detailed advisories and provided links for users to access patches and further information. The vulnerabilities were disclosed on October 21, 2025, and organizations are advised to act quickly to prevent potential exploitation. The missing authorization flaw specifically highlights the importance of robust authentication and session management in security appliances. Attackers exploiting this flaw could bypass intended access controls, undermining the security posture of affected networks. The command injection vulnerability, while requiring authentication, could allow attackers to execute arbitrary commands on the device, potentially leading to full system compromise. Both vulnerabilities underscore the need for regular firmware updates and vigilant monitoring of security advisories from vendors. Organizations should also review their 2FA implementations and ensure that partial authentication does not grant unintended access. The advisories recommend immediate patching as the primary mitigation step. Security teams are encouraged to audit their Zyxel device inventories and verify that all affected models are updated to the latest secure firmware versions. Failure to address these vulnerabilities could result in unauthorized access, data leakage, or further exploitation by threat actors. The coordinated disclosure and response from Zyxel and cybersecurity authorities aim to minimize the window of exposure for customers worldwide.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Zyxel ATP, USG FLEX, and USG20(W) devices were the subject of a security advisory covering CVE-2025-9133, a missing authorization vulnerability. The advisory was reflected by Canada's Cyber Centre and vulnerability tracking sources on the same date.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.