CVE-2025-13942

Published Feb 24, 2026

Last updated 2 months ago

CVSS critical 9.8
Network
Zyxel EX3510-B0
Zyxel

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-13942 is currently a reserved CVE identifier. This means that a CVE Numbering Authority (CNA) has allocated this ID for a potential vulnerability, but the specific details, such as the affected product, vulnerability type, and impact, have not yet been publicly disclosed or published in a CVE record. As such, there are no popular articles or detailed descriptions available for this particular CVE at this time.

Description
A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.
Source
security@zyxel.com.tw
NVD status
Analyzed
Products
wx5610-b0_firmware, lte3301-plus_firmware, nebula_lte3301-plus_firmware, nr7101_firmware, nebula_nr7101_firmware, dx4510-b0_firmware, dx4510-b1_firmware, ee6510-10_firmware, emg6726-b10a_firmware, ex2210-t0_firmware, ex3510-b0_firmware, ex3510-b1_firmware, ex5510-b0_firmware, ex5512-t0_firmware, ex7710-b0_firmware, vmg4927-b50a_firmware, px3321-t1_firmware, px5301-t0_firmware

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@zyxel.com.tw
CWE-78

Social media

Hype score
Not currently trending
  1. Zyxel Router の複数の脆弱性が FIX:OS コマンド実行や DoS 攻撃の恐れ https://t.co/BgPF0a6U7j Zyxel が、家庭用/ビジネス用のルーターやエクステンダーを含む、複数の製品に存在する深刻なリモートコード実行 (RCE) の

    @iototsecnews

    4 Mar 2026

    224 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-13942 (CVSS:9.8, CRITICAL) is Analyzed. A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C..https://t.co/SDwfRZW2W5 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    1 Mar 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2025-13942 (CVSS:9.8, CRITICAL) is Analyzed. A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C..https://t.co/SDwfRZW2W5 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    28 Feb 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. ⚠️ Vulnerabilidades en productos Zyxel ❗ CVE-2026-1459 ❗ CVE-2025-13943 ❗ CVE-2025-13942 ➡️ Más info: https://t.co/46G5AlbX0D https://t.co/Mm5XqgBCoc

    @CERTpy

    27 Feb 2026

    79 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 Zyxel patches critical UPnP command-injection bug enabling unauthenticated RCE on routers Zyxel shipped fixes for a critical UPnP command-injection flaw (CVE-2025-13942) affecting multiple CPE/router models that could let unauthenticated attackers execute OS commands via

    @ThreatSynop

    26 Feb 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 @zyxel patches critical CVE-2025-13942 RCE flaw affecting 12+ routers including 4G/5G, DSL/Ethernet, Fiber ONTs, wireless extenders. • Remote OS command execution via UPnP • Exploitation requires WAN + UPnP enabled • 120k+ exposed devices tracked globally Patch now &am

    @TechNadu

    26 Feb 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Critical Zyxel router vulnerability (CVE-2025-13942) exposes 120K+ devices to unauthenticated RCE. Implement network segmentation, isolate critical systems, deploy hardware firewalls, and maintain air-gapped backups. Verify firmware patches immediately. #TheSovereignProtocol

    @sovereignexec

    26 Feb 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 ALERTĂ: CVE-2025-13942 este o vulnerabilitate critică, cu scor CVSS v3.1 de 9.8, de tip “OS Command Injection” care afectează funcția Universal Plug and Play (UPnP) din mai multe echipamente Zyxel. 👉 https://t.co/dfOXw7pSxK #DNSC https://t.co/yDt3fgFgIq

    @DNSC_RO

    26 Feb 2026

    82 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 Zyxel Patches Critical 9.8 Command Injection Flaw Across Many Router/CPE Models Zyxel fixed multiple high-severity bugs—most notably CVE-2025-13942 (CVSS 9.8), an unauthenticated OS command injection in the UPnP service that can be exploited via crafted UPnP SOAP requests

    @ThreatSynop

    26 Feb 2026

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨 Zyxel Fixes Critical 9.8 RCE in Dozens of Devices via UPnP (CVE-2025-13942) Zyxel patched a critical OS command injection flaw (CVSS 9.8) in the UPnP feature that could allow remote attackers to execute OS commands via crafted UPnP SOAP requests—primarily if WAN access and

    @ThreatSynop

    26 Feb 2026

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Zyxel has released updates for over a dozen router models to fix a critical vulnerability, CVE-2025-13942, allowing remote command execution. While exploitation requires specific settings to be enabled, users should install the patches. Zyxel also addressed two high-severity

    @cybernewslive

    26 Feb 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨 Critical Zyxel router UPnP command-injection flaw enables unauth remote OS command execution Zyxel patched CVE-2025-13942 (CVSS 9.8), a UPnP command-injection bug affecting 4G/5G CPE, DSL/Ethernet CPE, Fiber ONTs, and wireless extenders that can allow unauth attackers to run

    @ThreatSynop

    25 Feb 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Zyxel patches critical RCE flaw CVE-2025-13942 impacting 4G/5G CPE, DSL/Ethernet CPE, fiber ONT, and wireless extenders. Exploits require UPnP and WAN enabled. End-of-life devices remain at risk. #ZyxelRouters #RemoteExec #USA https://t.co/QQQMyXZc22

    @TweetThreatNews

    25 Feb 2026

    116 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Zyxel patches critical RCE bug CVE-2025-13942 in UPnP affecting 4G/5G CPE, DSL/Ethernet CPE, Fiber ONTs and extenders, enabling unauthenticated remote OS command execution on routers. https://t.co/5YAd8wEZyD

    @threatcluster

    25 Feb 2026

    72 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CRITICAL CVE ALERT ‼️🚨 Zyxel has released security updates to address a critical vulnerability, CVE-2025-13942, which affects over a dozen router models. To find out more on how to patch, please visit the link below: https://t.co/PsyUcD6lKV

    @Cyber_Toolkit

    25 Feb 2026

    49 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🚨 Zyxel Patches Critical Router RCE Bug (CVE-2025-13942) Impacting 12+ Models Zyxel fixed a critical UPnP command-injection flaw (CVE-2025-13942) that allows unauthenticated remote OS command execution via crafted UPnP SOAP requests, but exploitation typically requires both UP

    @ThreatSynop

    25 Feb 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Zyxel社NW機器各種に重大(Critical)な脆弱性。CVE-2025-13942はCVSSスコア9.8で、UPnP SOAPリクエストにおけるコマンドインジェクション脆弱性。その他コマンドインジェクション等複数脆弱性と併せ修正。 https://t.co/dRU6c0

    @__kokumoto

    25 Feb 2026

    683 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  18. Zyxel issues urgent patches for a critical 9.8 severity flaw (CVE-2025-13942) in UPnP functions that allows remote attackers to execute OS commands. Patch now! #Zyxel #CyberSecurity #CVE202513942 #RouterSecurity #InfoSec #RCE #PatchAlert #Vulnerability https://t.co/sH3GbusWlN

    @the_yellow_fall

    25 Feb 2026

    170 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Zyxel has published 2 CVEs for some vulns I found :D CVE-2025-13943: Authenticated command injection in log export CGI CVE-2025-13942: Unauthenticated command injection in UPnP daemon I will blog about this in the coming months. Meanwhile, exploits here: https://t.co/CbVHekdN5q

    @hacefresko

    24 Feb 2026

    2068 Impressions

    13 Retweets

    37 Likes

    9 Bookmarks

    1 Reply

    0 Quotes

  20. CVE-2025-13942 A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute ope… https://t.co/zhenTwFhzu

    @CVEnew

    24 Feb 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. [CVE-2025-13942: CRITICAL] Critical vulnerability in Zyxel EX3510-B0 firmware allows remote attackers to execute OS commands via UPnP function. Update to version 5.17(ABUP.15.1)C0 to patch the issue.#cve,CVE-2025-13942,#cybersecurity https://t.co/ErrC3xhwrW

    @CveFindCom

    24 Feb 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. **CVE-2025-13942** is a command injection vulnerability affecting the UPnP (Universal Plug and Play) function in Zyxel EX3510-B0 firmware versions up to 5.17(ABUP.15.1)C0. This flaw allows a remote attacker to execute arbitrary operating system commands on the affected device by

    @CveTodo

    24 Feb 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations