CVE-2025-13943

HIGH EPSS 69.0%
Published Feb 24, 20264mo ago · Modified Jun 17, 20261w ago
8.8 CVSS 3.1
High
Find Similar
Published Feb 24, 2026 4mo ago
Last Modified Jun 17, 2026 1w ago

Description

A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device.

CVSS Details

Base Score
8.8
Exploitability
2.8
Impact
5.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
69.0% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-78 OS Command Injection Injection

Affected Products 106

VendorProductVersionRange
zyxelex5601-t1_firmware* <5.70\(acdz.5.1\)c0
zyxelex5601-t1*any
zyxelex7501-b0_firmware* <5.18\(achn.3.1\)c0
zyxelex7501-b0*any
zyxelex7710-b0_firmware* <5.18\(acak.1.6\)c0
zyxelex7710-b0*any
zyxelgm4100-b0_firmware* <5.18\(accl.2\)c0
zyxelgm4100-b0*any
zyxelpm7500-00_firmware* <5.61\(ackk.1.2\)c0
zyxelpm7500-00*any
zyxelvmg3625-t50b_firmware* <5.50\(abpm.9.7\)c0
zyxelvmg3625-t50b*any
zyxelvmg4005-b50a_firmware* <5.17\(abqa.3.2\)c0
zyxelvmg4005-b50a*any
zyxelvmg4005-b60a_firmware* <5.17\(abqa.3.2\)c0
zyxelvmg4005-b60a*any
zyxelax7501-b1_firmware* <5.17\(abpc.7.1\)c0
zyxelax7501-b1*any
zyxelpe3301-00_firmware* <5.63\(acmt.2.1\)c0
zyxelpe3301-00*any
zyxelpe5301-01_firmware* <5.63\(acoj.2.1\)c0
zyxelpe5301-01*any
zyxelpm3100-t0_firmware* <5.42\(acbf.4.1\)c0
zyxelpm3100-t0*any
zyxelpm5100-t0_firmware* <5.42\(acbf.4.1\)c0
zyxelpm5100-t0*any
zyxelpm5100-t1_firmware* <5.42\(acbf.4.1\)c0
zyxelpm5100-t1*any
zyxelpm7300-t0_firmware* <5.42\(abyy.4.1\)c0
zyxelpm7300-t0*any
zyxelpx3321-t1_firmware* <5.44\(achk.3\)c0
zyxelpx3321-t1*any
zyxelpx3321-t1_firmware* <5.44\(acjb.1.5\)c0
zyxelpx3321-t1*any
zyxelpx5301-t0_firmware* <5.44\(ackb.0.6\)c0
zyxelpx5301-t0*any
zyxelvmg8623-t50b_firmware* <5.50\(abpm.9.7\)c0
zyxelvmg8623-t50b*any
zyxelwe3300-00_firmware* <5.70\(acka.1.1\)c0
zyxelwe3300-00*any
zyxelwx3100-t0_firmware* <5.50\(abvl.4.9\)c0
zyxelwx3100-t0*any
zyxelwx3401-b1_firmware* <5.17\(abve.2.10\)c0
zyxelwx3401-b1*any
zyxelwx5600-t0_firmware* <5.70\(aceb.5.1\)c0
zyxelwx5600-t0*any
zyxelwx5610-b0_firmware* <5.18\(acgj.0.5\)c0
zyxelwx5610-b0*any
zyxeldm4200-b0_firmware* <5.17\(acbs.1.6\)c0
zyxeldm4200-b0*any
zyxelwe4600-00_firmware* <6.70\(ackt.0\)c0
zyxelwe4600-00*any
zyxelemg6726-b10a_firmware* <5.13\(abnp.8.2\)c1
zyxelemg6726-b10a*any
zyxelam7510-00_firmware* <5.63\(acoe.0.1\)c0
zyxelam7510-00*any
zyxelvmg4927-b50a_firmware* <5.13\(ably.10.2\)c0
zyxelvmg4927-b50a*any
zyxelex5601-t0_firmware* <5.70\(acdz.5.1\)c0
zyxelex5601-t0*any
zyxelex5512-t0_firmware* <5.70\(aceg.5.3\)c0
zyxelex5512-t0*any
zyxelex5510-b0_firmware* <5.17\(abqx.11.1\)c0
zyxelex5510-b0*any
zyxelex5401-b1_firmware* <5.17\(abyo.7.1\)c0
zyxelex5401-b1*any
zyxelex3600-t0_firmware* <5.70\(acif.2.1\)c0
zyxelex3600-t0*any
zyxelex3510-b1_firmware* <5.17\(abup.15.2\)c0
zyxelex3510-b1*any
zyxelex3510-b0_firmware* <5.17\(abup.15.2\)c0
zyxelex3510-b0*any
zyxelex3501-t0_firmware* <5.44\(achr.5.1\)c0
zyxelex3501-t0*any
zyxelex3500-t0_firmware* <5.44\(achr.5.1\)c0
zyxelex3500-t0*any
zyxelex3301-t0_firmware* <5.50\(abvy.7.1\)c0
zyxelex3301-t0*any
zyxelex3300-t1_firmware* <5.50\(abvy.7.1\)c0
zyxelex3300-t1*any
zyxelex3300-t0_firmware* <5.50\(abvy.7.1\)c0
zyxelex3300-t0*any
zyxelex2210-t0_firmware* <5.50\(acdi.2.3\)c0
zyxelex2210-t0*any
zyxelemg5523-t50b_firmware* <5.50\(abpm.9.7\)c0
zyxelemg5523-t50b*any
zyxelemg3525-t50b_firmware* <5.50\(abpm.9.7\)c0
zyxelemg3525-t50b*any
zyxelee6510-10_firmware* <5.19\(acjq.4.1\)c0
zyxelee6510-10*any
zyxeldx3300-t0_firmware* <5.50\(abvy.7.1\)c0
zyxeldx3300-t0*any
zyxeldx3300-t1_firmware* <5.50\(abvy.7.1\)c0
zyxeldx3300-t1*any
zyxeldx3301-t0_firmware* <5.50\(abvy.7.1\)c0
zyxeldx3301-t0*any
zyxeldx4510-b0_firmware* <5.17\(abyl.10.1\)c0
zyxeldx4510-b0*any
zyxeldx4510-b1_firmware* <5.17\(abyl.10.1\)c0
zyxeldx4510-b1*any
zyxeldx5401-b1_firmware* <5.17\(abyo.7.1\)c0
zyxeldx5401-b1*any
zyxelee3301-00_firmware* <5.63\(acmu.2.1\)c0
zyxelee3301-00*any
zyxelee5301-00_firmware* <5.63\(acld.2.1\)c0
zyxelee5301-00*any

References 1

  • zyxel.com https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-null-pointer-dereference-and-command-injection-vulnerabilities-in-certain-4g-lte-5g-nr-cpe-dsl-ethernet-cpe-fiber-onts-security-routers-and-wireless-extenders-02-24-2026
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.