CVE-2025-13942
A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.06%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.06% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- zyxel/wx5610-b0 firmware · zyxel/lte3301-plus firmware · zyxel/nebula lte3301-plus firmware · zyxel/nr7101 firmware · zyxel/nebula nr7101 firmware · zyxel/dx4510-b0 firmware · zyxel/dx4510-b1 firmware · zyxel/ee6510-10 firmware · zyxel/emg6726-b10a firmware · zyxel/ex2210-t0 firmware · zyxel/ex3510-b0 firmware · zyxel/ex3510-b1 firmware · zyxel/ex5510-b0 firmware · zyxel/ex5512-t0 firmware · zyxel/ex7710-b0 firmware · zyxel/vmg4927-b50a firmware · zyxel/px3321-t1 firmware · zyxel/px5301-t0 firmware
- Source
- security@zyxel.com.tw
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.