CVE Feed

    Dashboard / CVE / CVE-2025-13942

    CVE-2025-13942

    A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.

    Published:Feb 24, 2026
    Last Modified:Feb 26, 2026
    EPS:Feb 24, 2026
    EPSS Score:0.0034
    CVSS Score:9.8

    Affected Products

    Vendor
    Zyxel
    Product
    Dx4510-b0
    Vendor
    Zyxel
    Product
    Dx4510-b0 Firmware
    Vendor
    Zyxel
    Product
    Dx4510-b1
    Vendor
    Zyxel
    Product
    Dx4510-b1 Firmware
    Vendor
    Zyxel
    Product
    Ee6510-10
    Vendor
    Zyxel
    Product
    Ee6510-10 Firmware
    Vendor
    Zyxel
    Product
    Emg6726-b10a
    Vendor
    Zyxel
    Product
    Emg6726-b10a Firmware
    Vendor
    Zyxel
    Product
    Ex2210-t0
    Vendor
    Zyxel
    Product
    Ex2210-t0 Firmware
    Vendor
    Zyxel
    Product
    Ex3510-b0
    Vendor
    Zyxel
    Product
    Ex3510-b0 Firmware
    Vendor
    Zyxel
    Product
    Ex3510-b1
    Vendor
    Zyxel
    Product
    Ex3510-b1 Firmware
    Vendor
    Zyxel
    Product
    Ex5510-b0
    Vendor
    Zyxel
    Product
    Ex5510-b0 Firmware
    Vendor
    Zyxel
    Product
    Ex5512-t0
    Vendor
    Zyxel
    Product
    Ex5512-t0 Firmware
    Vendor
    Zyxel
    Product
    Ex7710-b0
    Vendor
    Zyxel
    Product
    Ex7710-b0 Firmware
    Vendor
    Zyxel
    Product
    Lte3301-plus
    Vendor
    Zyxel
    Product
    Lte3301-plus Firmware
    Vendor
    Zyxel
    Product
    Nebula Lte3301-plus
    Vendor
    Zyxel
    Product
    Nebula Lte3301-plus Firmware
    Vendor
    Zyxel
    Product
    Nebula Nr7101
    Vendor
    Zyxel
    Product
    Nebula Nr7101 Firmware
    Vendor
    Zyxel
    Product
    Nr7101
    Vendor
    Zyxel
    Product
    Nr7101 Firmware
    Vendor
    Zyxel
    Product
    Px3321-t1
    Vendor
    Zyxel
    Product
    Px3321-t1 Firmware
    Vendor
    Zyxel
    Product
    Px5301-t0
    Vendor
    Zyxel
    Product
    Px5301-t0 Firmware
    Vendor
    Zyxel
    Product
    Vmg4927-b50a
    Vendor
    Zyxel
    Product
    Vmg4927-b50a Firmware
    Vendor
    Zyxel
    Product
    Wx5610-b0
    Vendor
    Zyxel
    Product
    Wx5610-b0 Firmware

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High