Description

A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.

INFO

Published Date :

2026-02-24T02:32:18.934Z

Last Modified :

2026-02-26T14:44:10.318Z

Source :

Zyxel
AFFECTED PRODUCTS

The following products are affected by CVE-2025-13942 vulnerability.

Vendors Products
Zyxel
  • Dx4510-b0
  • Dx4510-b0 Firmware
  • Dx4510-b1
  • Dx4510-b1 Firmware
  • Ee6510-10
  • Ee6510-10 Firmware
  • Emg6726-b10a
  • Emg6726-b10a Firmware
  • Ex2210-t0
  • Ex2210-t0 Firmware
  • Ex3510-b0
  • Ex3510-b0 Firmware
  • Ex3510-b1
  • Ex3510-b1 Firmware
  • Ex5510-b0
  • Ex5510-b0 Firmware
  • Ex5512-t0
  • Ex5512-t0 Firmware
  • Ex7710-b0
  • Ex7710-b0 Firmware
  • Lte3301-plus
  • Lte3301-plus Firmware
  • Nebula Lte3301-plus
  • Nebula Lte3301-plus Firmware
  • Nebula Nr7101
  • Nebula Nr7101 Firmware
  • Nr7101
  • Nr7101 Firmware
  • Px3321-t1
  • Px3321-t1 Firmware
  • Px5301-t0
  • Px5301-t0 Firmware
  • Vmg4927-b50a
  • Vmg4927-b50a Firmware
  • Wx5610-b0
  • Wx5610-b0 Firmware

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact