CVE-2025-13943
A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- zyxel/ex5601-t1 firmware · zyxel/ex7501-b0 firmware · zyxel/ex7710-b0 firmware · zyxel/gm4100-b0 firmware · zyxel/pm7500-00 firmware · zyxel/vmg3625-t50b firmware · zyxel/vmg4005-b50a firmware · zyxel/vmg4005-b60a firmware · zyxel/ax7501-b1 firmware · zyxel/pe3301-00 firmware · zyxel/pe5301-01 firmware · zyxel/pm3100-t0 firmware · zyxel/pm5100-t0 firmware · zyxel/pm5100-t1 firmware · zyxel/pm7300-t0 firmware · zyxel/px3321-t1 firmware · zyxel/px5301-t0 firmware · zyxel/vmg8623-t50b firmware · zyxel/we3300-00 firmware · zyxel/wx3100-t0 firmware · +32 more
- Source
- security@zyxel.com.tw
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.