CVE-2025-13942: OS Command Injection
A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13942?
CVE-2025-13942 has been rated as critical due to its potential for remote command execution.
How do I fix CVE-2025-13942?
To fix CVE-2025-13942, update your Zyxel EX3510-B0 firmware to a version later than 5.17(ABUP.15.1)C0.
What device is affected by CVE-2025-13942?
CVE-2025-13942 affects the Zyxel EX3510-B0 firmware versions up to and including 5.17(ABUP.15.1)C0.
What type of vulnerability is CVE-2025-13942?
CVE-2025-13942 is a command injection vulnerability that allows remote attackers to execute OS commands.
What can an attacker do with CVE-2025-13942?
An attacker can execute arbitrary operating system commands on the affected device by sending specially crafted UPnP SOAP requests.