CVE-2025-13942: Zyxel DX4510-b0 Firmware

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.

Affected products

  • Zyxel DX4510-b0 Firmware: before 5.17\(abyl.10.1\)c0 (fixed in 5.17\(abyl.10.1\)c0)
  • Zyxel DX4510-b1 Firmware: before 5.17\(abyl.10.1\)c0 (fixed in 5.17\(abyl.10.1\)c0)
  • Zyxel EE6510-10 Firmware: before 5.19\(acjq.4.1\)c0 (fixed in 5.19\(acjq.4.1\)c0)
  • Zyxel EMG6726-b10a Firmware: before 5.13\(abnp.8.2\)c1 (fixed in 5.13\(abnp.8.2\)c1)
  • Zyxel EX2210-t0 Firmware: before 5.50\(acdi.2.4\)c0 (fixed in 5.50\(acdi.2.4\)c0)
  • Zyxel EX3510-b0 Firmware: before 5.17\(abup.15.2\)c0 (fixed in 5.17\(abup.15.2\)c0)
  • Zyxel EX3510-b1 Firmware: before 5.17\(abup.15.2\)c0 (fixed in 5.17\(abup.15.2\)c0)
  • Zyxel EX5510-b0 Firmware: before 5.17\(abqx.11.1\)c0 (fixed in 5.17\(abqx.11.1\)c0)
  • Zyxel EX5512-t0 Firmware: before 5.70\(aceg.5.4\)c0 (fixed in 5.70\(aceg.5.4\)c0)
  • Zyxel EX7710-b0 Firmware: before 5.18\(acak.1.6\)c0 (fixed in 5.18\(acak.1.6\)c0)
  • Zyxel LTE3301-Plus Firmware: before 1.00\(abqu.9\)c0 (fixed in 1.00\(abqu.9\)c0)
  • Zyxel Nebula LTE3301-Plus Firmware: before 1.18\(acca.6\)v0 (fixed in 1.18\(acca.6\)v0)
  • Zyxel Nebula NR7101 Firmware: before 1.16\(accc.1\)v0 (fixed in 1.16\(accc.1\)v0)
  • Zyxel NR7101 Firmware: before 1.00\(abuv.12\)b2 (fixed in 1.00\(abuv.12\)b2)
  • Zyxel PX3321-t1 Firmware: before 5.44\(acjb.1.5\)c0 (fixed in 5.44\(acjb.1.5\)c0); before 5.44\(achk.3\)c0 (fixed in 5.44\(achk.3\)c0)
  • Zyxel PX5301-t0 Firmware: before 5.44\(ackb.0.6\)c0 (fixed in 5.44\(ackb.0.6\)c0)
  • Zyxel VMG4927-b50a Firmware: before 5.13\(ably.10.2\)c0 (fixed in 5.13\(ably.10.2\)c0)
  • Zyxel WX5610-b0 Firmware: before 5.18\(acgj.0.5\)c0 (fixed in 5.18\(acgj.0.5\)c0)

Published 2026-02-24. Last modified 2026-06-17.