logo

Critical ZLAN5143D Flaws (CVSS 9.8) Allow Total Takeover, No Patch Available

ID: 087f3c59-d002-50a7-ab19-61ccec5d0796

STIX ID: report--087f3c59-d002-50a7-ab19-61ccec5d0796

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-16

Date Updated: 2026-04-23

Author: Ddos

...
...

CISA warns of two critical vulnerabilities in the ZLAN5143D serial-to-ethernet server (CVE-2026-25084 and CVE-2026-24789) — one enables authentication bypass via direct access to internal URLs and the other allows remote password resets through an unprotected API — both rated CVSS 9.8; the vendor did not respond to coordination, no patch is confirmed, and administrators are advised to isolate these devices from the public internet and restrict management access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.