VYPR

EX3301-T0

by Zyxel

CVEs (2)

  • CVE-2026-1460HigApr 28, 2026
    risk 0.47cvss 7.2epss 0.00

    A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

  • CVE-2025-13943Feb 24, 2026
    risk 0.00cvss epss 0.00

    A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device.