9.8

CVE-2025-13942

A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZyxelWx5610-b0 Firmware Version < 5.18\(acgj.0.5\)c0
   ZyxelWx5610-b0 Version-
ZyxelLte3301-plus Firmware Version < 1.00\(abqu.9\)c0
   ZyxelLte3301-plus Version-
ZyxelNebula Lte3301-plus Firmware Version < 1.18\(acca.6\)v0
   ZyxelNebula Lte3301-plus Version-
ZyxelNr7101 Firmware Version < 1.00\(abuv.12\)b2
   ZyxelNr7101 Version-
ZyxelNebula Nr7101 Firmware Version < 1.16\(accc.1\)v0
   ZyxelNebula Nr7101 Version-
ZyxelDx4510-b0 Firmware Version < 5.17\(abyl.10.1\)c0
   ZyxelDx4510-b0 Version-
ZyxelDx4510-b1 Firmware Version < 5.17\(abyl.10.1\)c0
   ZyxelDx4510-b1 Version-
ZyxelEe6510-10 Firmware Version < 5.19\(acjq.4.1\)c0
   ZyxelEe6510-10 Version-
ZyxelEmg6726-b10a Firmware Version < 5.13\(abnp.8.2\)c1
   ZyxelEmg6726-b10a Version-
ZyxelEx2210-t0 Firmware Version < 5.50\(acdi.2.4\)c0
   ZyxelEx2210-t0 Version-
ZyxelEx3510-b0 Firmware Version < 5.17\(abup.15.2\)c0
   ZyxelEx3510-b0 Version-
ZyxelEx3510-b1 Firmware Version < 5.17\(abup.15.2\)c0
   ZyxelEx3510-b1 Version-
ZyxelEx5510-b0 Firmware Version < 5.17\(abqx.11.1\)c0
   ZyxelEx5510-b0 Version-
ZyxelEx5512-t0 Firmware Version < 5.70\(aceg.5.4\)c0
   ZyxelEx5512-t0 Version-
ZyxelEx7710-b0 Firmware Version < 5.18\(acak.1.6\)c0
   ZyxelEx7710-b0 Version-
ZyxelVmg4927-b50a Firmware Version < 5.13\(ably.10.2\)c0
   ZyxelVmg4927-b50a Version-
ZyxelPx3321-t1 Firmware Version < 5.44\(acjb.1.5\)c0
   ZyxelPx3321-t1 Version-
ZyxelPx3321-t1 Firmware Version < 5.44\(achk.3\)c0
   ZyxelPx3321-t1 Version-
ZyxelPx5301-t0 Firmware Version < 5.44\(ackb.0.6\)c0
   ZyxelPx5301-t0 Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.395
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
security@zyxel.com.tw 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.