CVE-2025-13943

EUVD-2025-207550
A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
zyxelee5301-00_firmware
𝑥
< 5.63\(acld.2.1\)c0
zyxelee3301-00_firmware
𝑥
< 5.63\(acmu.2.1\)c0
zyxeldx5401-b1_firmware
𝑥
< 5.17\(abyo.7.1\)c0
zyxeldx4510-b1_firmware
𝑥
< 5.17\(abyl.10.1\)c0
zyxeldx4510-b0_firmware
𝑥
< 5.17\(abyl.10.1\)c0
zyxeldx3301-t0_firmware
𝑥
< 5.50\(abvy.7.1\)c0
zyxeldx3300-t1_firmware
𝑥
< 5.50\(abvy.7.1\)c0
zyxeldx3300-t0_firmware
𝑥
< 5.50\(abvy.7.1\)c0
zyxelee6510-10_firmware
𝑥
< 5.19\(acjq.4.1\)c0
zyxelemg3525-t50b_firmware
𝑥
< 5.50\(abpm.9.7\)c0
zyxelemg5523-t50b_firmware
𝑥
< 5.50\(abpm.9.7\)c0
zyxelex2210-t0_firmware
𝑥
< 5.50\(acdi.2.3\)c0
zyxelex3300-t0_firmware
𝑥
< 5.50\(abvy.7.1\)c0
zyxelex3300-t1_firmware
𝑥
< 5.50\(abvy.7.1\)c0
zyxelex3301-t0_firmware
𝑥
< 5.50\(abvy.7.1\)c0
zyxelex3500-t0_firmware
𝑥
< 5.44\(achr.5.1\)c0
zyxelex3501-t0_firmware
𝑥
< 5.44\(achr.5.1\)c0
zyxelex3510-b0_firmware
𝑥
< 5.17\(abup.15.2\)c0
zyxelex3510-b1_firmware
𝑥
< 5.17\(abup.15.2\)c0
zyxelex3600-t0_firmware
𝑥
< 5.70\(acif.2.1\)c0
zyxelex5401-b1_firmware
𝑥
< 5.17\(abyo.7.1\)c0
zyxelex5510-b0_firmware
𝑥
< 5.17\(abqx.11.1\)c0
zyxelex5512-t0_firmware
𝑥
< 5.70\(aceg.5.3\)c0
zyxelex5601-t0_firmware
𝑥
< 5.70\(acdz.5.1\)c0
zyxelex5601-t1_firmware
𝑥
< 5.70\(acdz.5.1\)c0
zyxelex7501-b0_firmware
𝑥
< 5.18\(achn.3.1\)c0
zyxelex7710-b0_firmware
𝑥
< 5.18\(acak.1.6\)c0
zyxelgm4100-b0_firmware
𝑥
< 5.18\(accl.2\)c0
zyxelpm7500-00_firmware
𝑥
< 5.61\(ackk.1.2\)c0
zyxelvmg3625-t50b_firmware
𝑥
< 5.50\(abpm.9.7\)c0
zyxelvmg4005-b50a_firmware
𝑥
< 5.17\(abqa.3.2\)c0
zyxelvmg4005-b60a_firmware
𝑥
< 5.17\(abqa.3.2\)c0
zyxelax7501-b1_firmware
𝑥
< 5.17\(abpc.7.1\)c0
zyxelpe3301-00_firmware
𝑥
< 5.63\(acmt.2.1\)c0
zyxelpe5301-01_firmware
𝑥
< 5.63\(acoj.2.1\)c0
zyxelpm3100-t0_firmware
𝑥
< 5.42\(acbf.4.1\)c0
zyxelpm5100-t0_firmware
𝑥
< 5.42\(acbf.4.1\)c0
zyxelpm5100-t1_firmware
𝑥
< 5.42\(acbf.4.1\)c0
zyxelpm7300-t0_firmware
𝑥
< 5.42\(abyy.4.1\)c0
zyxelpx3321-t1_firmware
𝑥
< 5.44\(achk.3\)c0
zyxelpx3321-t1_firmware
𝑥
< 5.44\(acjb.1.5\)c0
zyxelpx5301-t0_firmware
𝑥
< 5.44\(ackb.0.6\)c0
zyxelvmg8623-t50b_firmware
𝑥
< 5.50\(abpm.9.7\)c0
zyxelwe3300-00_firmware
𝑥
< 5.70\(acka.1.1\)c0
zyxelwx3100-t0_firmware
𝑥
< 5.50\(abvl.4.9\)c0
zyxelwx3401-b1_firmware
𝑥
< 5.17\(abve.2.10\)c0
zyxelwx5600-t0_firmware
𝑥
< 5.70\(aceb.5.1\)c0
zyxelwx5610-b0_firmware
𝑥
< 5.18\(acgj.0.5\)c0
zyxeldm4200-b0_firmware
𝑥
< 5.17\(acbs.1.6\)c0
zyxelwe4600-00_firmware
𝑥
< 6.70\(ackt.0\)c0
zyxelemg6726-b10a_firmware
𝑥
< 5.13\(abnp.8.2\)c1
zyxelam7510-00_firmware
𝑥
< 5.63\(acoe.0.1\)c0
zyxelvmg4927-b50a_firmware
𝑥
< 5.13\(ably.10.2\)c0
𝑥
= Vulnerable software versions