Critical ZLAN5143D Flaws (CVSS 9.8) Allow Total Takeover, No Patch Available
ID: 087f3c59-d002-50a7-ab19-61ccec5d0796
STIX ID: report--087f3c59-d002-50a7-ab19-61ccec5d0796
Feed Name: securityonline.info
Threat Score
CISA warns of two critical vulnerabilities in the ZLAN5143D serial-to-ethernet server (CVE-2026-25084 and CVE-2026-24789) — one enables authentication bypass via direct access to internal URLs and the other allows remote password resets through an unprotected API — both rated CVSS 9.8; the vendor did not respond to coordination, no patch is confirmed, and administrators are advised to isolate these devices from the public internet and restrict management access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
