PatchSiren

ZLAN Information Technology Co. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL ZLAN Information Technology Co. CVE published 2026-02-10

CVE-2026-25084

CVE-2026-25084 is a critical authentication-bypass issue affecting ZLAN Information Technology Co. ZLAN5143D devices. According to the CISA CSAF advisory, authentication can be bypassed by directly accessing internal URLs, which can allow an unauthenticated attacker to reach functionality that should be protected.

CRITICAL ZLAN Information Technology Co. CVE published 2026-02-10

CVE-2026-24789

CVE-2026-24789 is a critical authentication-bypass issue in ZLAN Information Technology Co. ZLAN5143D devices. According to CISA’s advisory, an unprotected API endpoint allows a remote attacker to change the device password without providing authentication. The CVSS v3.1 score is 9.8, reflecting network reachability, no required privileges, no user interaction, and high impact to confidentiality, integrit [truncated]