CVE-2025-13942

EUVD-2025-207551
A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
zyxelwx5610-b0_firmware
𝑥
< 5.18\(acgj.0.5\)c0
zyxellte3301-plus_firmware
𝑥
< 1.00\(abqu.9\)c0
zyxelnebula_lte3301-plus_firmware
𝑥
< 1.18\(acca.6\)v0
zyxelnr7101_firmware
𝑥
< 1.00\(abuv.12\)b2
zyxelnebula_nr7101_firmware
𝑥
< 1.16\(accc.1\)v0
zyxeldx4510-b0_firmware
𝑥
< 5.17\(abyl.10.1\)c0
zyxeldx4510-b1_firmware
𝑥
< 5.17\(abyl.10.1\)c0
zyxelee6510-10_firmware
𝑥
< 5.19\(acjq.4.1\)c0
zyxelemg6726-b10a_firmware
𝑥
< 5.13\(abnp.8.2\)c1
zyxelex2210-t0_firmware
𝑥
< 5.50\(acdi.2.4\)c0
zyxelex3510-b0_firmware
𝑥
< 5.17\(abup.15.2\)c0
zyxelex3510-b1_firmware
𝑥
< 5.17\(abup.15.2\)c0
zyxelex5510-b0_firmware
𝑥
< 5.17\(abqx.11.1\)c0
zyxelex5512-t0_firmware
𝑥
< 5.70\(aceg.5.4\)c0
zyxelex7710-b0_firmware
𝑥
< 5.18\(acak.1.6\)c0
zyxelvmg4927-b50a_firmware
𝑥
< 5.13\(ably.10.2\)c0
zyxelpx3321-t1_firmware
𝑥
< 5.44\(acjb.1.5\)c0
zyxelpx3321-t1_firmware
𝑥
< 5.44\(achk.3\)c0
zyxelpx5301-t0_firmware
𝑥
< 5.44\(ackb.0.6\)c0
𝑥
= Vulnerable software versions