CVE-2025-13943

HIGH WAF: High
CVSS 8.8 Published: 2026-02-24
CWE-78

A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device.

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
zyxelee5301-00_firmwareup to 5.63\(acld.2.1\)c0
zyxelee3301-00_firmwareup to 5.63\(acmu.2.1\)c0
zyxeldx5401-b1_firmwareup to 5.17\(abyo.7.1\)c0
zyxeldx4510-b1_firmwareup to 5.17\(abyl.10.1\)c0
zyxeldx4510-b0_firmwareup to 5.17\(abyl.10.1\)c0
zyxeldx3301-t0_firmwareup to 5.50\(abvy.7.1\)c0
zyxeldx3300-t1_firmwareup to 5.50\(abvy.7.1\)c0
zyxeldx3300-t0_firmwareup to 5.50\(abvy.7.1\)c0
zyxelee6510-10_firmwareup to 5.19\(acjq.4.1\)c0
zyxelemg3525-t50b_firmwareup to 5.50\(abpm.9.7\)c0

References

Back to CVE Database