A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.
History

Wed, 25 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Zyxel dx4510-b0
Zyxel dx4510-b0 Firmware
Zyxel dx4510-b1
Zyxel dx4510-b1 Firmware
Zyxel ee6510-10
Zyxel ee6510-10 Firmware
Zyxel emg6726-b10a
Zyxel emg6726-b10a Firmware
Zyxel ex2210-t0
Zyxel ex2210-t0 Firmware
Zyxel ex3510-b0
Zyxel ex3510-b1
Zyxel ex3510-b1 Firmware
Zyxel ex5510-b0
Zyxel ex5510-b0 Firmware
Zyxel ex5512-t0
Zyxel ex5512-t0 Firmware
Zyxel ex7710-b0
Zyxel ex7710-b0 Firmware
Zyxel lte3301-plus
Zyxel lte3301-plus Firmware
Zyxel nebula Lte3301-plus
Zyxel nebula Lte3301-plus Firmware
Zyxel nebula Nr7101
Zyxel nebula Nr7101 Firmware
Zyxel nr7101
Zyxel nr7101 Firmware
Zyxel px3321-t1
Zyxel px3321-t1 Firmware
Zyxel px5301-t0
Zyxel px5301-t0 Firmware
Zyxel vmg4927-b50a
Zyxel vmg4927-b50a Firmware
Zyxel wx5610-b0
Zyxel wx5610-b0 Firmware
CPEs cpe:2.3:h:zyxel:dx4510-b0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:dx4510-b1:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ee6510-10:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:emg6726-b10a:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ex2210-t0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ex3510-b0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ex3510-b1:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ex5510-b0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ex5512-t0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ex7710-b0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:lte3301-plus:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:nebula_lte3301-plus:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:nebula_nr7101:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:nr7101:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:px3321-t1:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:px5301-t0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg4927-b50a:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:wx5610-b0:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:dx4510-b0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:dx4510-b1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ee6510-10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:emg6726-b10a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ex2210-t0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ex3510-b0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ex3510-b1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ex5510-b0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ex5512-t0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ex7710-b0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:lte3301-plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nebula_lte3301-plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nebula_nr7101_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nr7101_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:px3321-t1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:px5301-t0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg4927-b50a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:wx5610-b0_firmware:*:*:*:*:*:*:*:*
Vendors & Products Zyxel dx4510-b0
Zyxel dx4510-b0 Firmware
Zyxel dx4510-b1
Zyxel dx4510-b1 Firmware
Zyxel ee6510-10
Zyxel ee6510-10 Firmware
Zyxel emg6726-b10a
Zyxel emg6726-b10a Firmware
Zyxel ex2210-t0
Zyxel ex2210-t0 Firmware
Zyxel ex3510-b0
Zyxel ex3510-b1
Zyxel ex3510-b1 Firmware
Zyxel ex5510-b0
Zyxel ex5510-b0 Firmware
Zyxel ex5512-t0
Zyxel ex5512-t0 Firmware
Zyxel ex7710-b0
Zyxel ex7710-b0 Firmware
Zyxel lte3301-plus
Zyxel lte3301-plus Firmware
Zyxel nebula Lte3301-plus
Zyxel nebula Lte3301-plus Firmware
Zyxel nebula Nr7101
Zyxel nebula Nr7101 Firmware
Zyxel nr7101
Zyxel nr7101 Firmware
Zyxel px3321-t1
Zyxel px3321-t1 Firmware
Zyxel px5301-t0
Zyxel px5301-t0 Firmware
Zyxel vmg4927-b50a
Zyxel vmg4927-b50a Firmware
Zyxel wx5610-b0
Zyxel wx5610-b0 Firmware

Tue, 24 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 24 Feb 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Zyxel
Zyxel ex3510-b0 Firmware
Vendors & Products Zyxel
Zyxel ex3510-b0 Firmware

Tue, 24 Feb 2026 03:00:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published:

Updated: 2026-02-25T04:55:37.027Z

Reserved: 2025-12-03T05:28:13.264Z

Link: CVE-2025-13942

cve-icon Vulnrichment

Updated: 2026-02-24T16:04:51.639Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-24T03:16:00.223

Modified: 2026-02-25T18:13:10.563

Link: CVE-2025-13942

cve-icon Redhat

No data.