Critical severity9.8NVD Advisory· Published Feb 24, 2026· Updated Jun 17, 2026
CVE-2025-13942
CVE-2025-13942
Description
A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
20- cpe:2.3:o:zyxel:wx5610-b0_firmware:*:*:*:*:*:*:*:*Range: <5.18\(acgj.0.5\)c0
- cpe:2.3:o:zyxel:lte3301-plus_firmware:*:*:*:*:*:*:*:*Range: <1.00\(abqu.9\)c0
- cpe:2.3:o:zyxel:nebula_lte3301-plus_firmware:*:*:*:*:*:*:*:*Range: <1.18\(acca.6\)v0
- cpe:2.3:o:zyxel:nebula_nr7101_firmware:*:*:*:*:*:*:*:*Range: <1.16\(accc.1\)v0
- cpe:2.3:o:zyxel:dx4510-b0_firmware:*:*:*:*:*:*:*:*Range: <5.17\(abyl.10.1\)c0
- cpe:2.3:o:zyxel:dx4510-b1_firmware:*:*:*:*:*:*:*:*Range: <5.17\(abyl.10.1\)c0
- cpe:2.3:o:zyxel:ee6510-10_firmware:*:*:*:*:*:*:*:*Range: <5.19\(acjq.4.1\)c0
- cpe:2.3:o:zyxel:emg6726-b10a_firmware:*:*:*:*:*:*:*:*Range: <5.13\(abnp.8.2\)c1
- cpe:2.3:o:zyxel:ex2210-t0_firmware:*:*:*:*:*:*:*:*Range: <5.50\(acdi.2.4\)c0
cpe:2.3:o:zyxel:ex3510-b0_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:zyxel:ex3510-b0_firmware:*:*:*:*:*:*:*:*range: <5.17\(abup.15.2\)c0
- (no CPE)range: <= 5.17(ABUP.15.1)C0
- cpe:2.3:o:zyxel:ex3510-b1_firmware:*:*:*:*:*:*:*:*Range: <5.17\(abup.15.2\)c0
- cpe:2.3:o:zyxel:ex5510-b0_firmware:*:*:*:*:*:*:*:*Range: <5.17\(abqx.11.1\)c0
- cpe:2.3:o:zyxel:ex5512-t0_firmware:*:*:*:*:*:*:*:*Range: <5.70\(aceg.5.4\)c0
- cpe:2.3:o:zyxel:ex7710-b0_firmware:*:*:*:*:*:*:*:*Range: <5.18\(acak.1.6\)c0
- cpe:2.3:o:zyxel:vmg4927-b50a_firmware:*:*:*:*:*:*:*:*Range: <5.13\(ably.10.2\)c0
- cpe:2.3:o:zyxel:px3321-t1_firmware:*:*:*:*:*:*:*:*Range: <5.44\(acjb.1.5\)c0
- cpe:2.3:o:zyxel:px5301-t0_firmware:*:*:*:*:*:*:*:*Range: <5.44\(ackb.0.6\)c0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.