A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 25 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Zyxel dx4510-b0
Zyxel dx4510-b0 Firmware
Zyxel dx4510-b1
Zyxel dx4510-b1 Firmware
Zyxel ee6510-10
Zyxel ee6510-10 Firmware
Zyxel emg6726-b10a
Zyxel emg6726-b10a Firmware
Zyxel ex2210-t0
Zyxel ex2210-t0 Firmware
Zyxel ex3510-b0
Zyxel ex3510-b1
Zyxel ex3510-b1 Firmware
Zyxel ex5510-b0
Zyxel ex5510-b0 Firmware
Zyxel ex5512-t0
Zyxel ex5512-t0 Firmware
Zyxel ex7710-b0
Zyxel ex7710-b0 Firmware
Zyxel lte3301-plus
Zyxel lte3301-plus Firmware
Zyxel nebula Lte3301-plus
Zyxel nebula Lte3301-plus Firmware
Zyxel nebula Nr7101
Zyxel nebula Nr7101 Firmware
Zyxel nr7101
Zyxel nr7101 Firmware
Zyxel px3321-t1
Zyxel px3321-t1 Firmware
Zyxel px5301-t0
Zyxel px5301-t0 Firmware
Zyxel vmg4927-b50a
Zyxel vmg4927-b50a Firmware
Zyxel wx5610-b0
Zyxel wx5610-b0 Firmware
CPEs cpe:2.3:h:zyxel:dx4510-b0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:dx4510-b1:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ee6510-10:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:emg6726-b10a:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ex2210-t0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ex3510-b0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ex3510-b1:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ex5510-b0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ex5512-t0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ex7710-b0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:lte3301-plus:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:nebula_lte3301-plus:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:nebula_nr7101:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:nr7101:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:px3321-t1:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:px5301-t0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg4927-b50a:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:wx5610-b0:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:dx4510-b0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:dx4510-b1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ee6510-10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:emg6726-b10a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ex2210-t0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ex3510-b0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ex3510-b1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ex5510-b0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ex5512-t0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ex7710-b0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:lte3301-plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nebula_lte3301-plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nebula_nr7101_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nr7101_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:px3321-t1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:px5301-t0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg4927-b50a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:wx5610-b0_firmware:*:*:*:*:*:*:*:*
Vendors & Products Zyxel dx4510-b0
Zyxel dx4510-b0 Firmware
Zyxel dx4510-b1
Zyxel dx4510-b1 Firmware
Zyxel ee6510-10
Zyxel ee6510-10 Firmware
Zyxel emg6726-b10a
Zyxel emg6726-b10a Firmware
Zyxel ex2210-t0
Zyxel ex2210-t0 Firmware
Zyxel ex3510-b0
Zyxel ex3510-b1
Zyxel ex3510-b1 Firmware
Zyxel ex5510-b0
Zyxel ex5510-b0 Firmware
Zyxel ex5512-t0
Zyxel ex5512-t0 Firmware
Zyxel ex7710-b0
Zyxel ex7710-b0 Firmware
Zyxel lte3301-plus
Zyxel lte3301-plus Firmware
Zyxel nebula Lte3301-plus
Zyxel nebula Lte3301-plus Firmware
Zyxel nebula Nr7101
Zyxel nebula Nr7101 Firmware
Zyxel nr7101
Zyxel nr7101 Firmware
Zyxel px3321-t1
Zyxel px3321-t1 Firmware
Zyxel px5301-t0
Zyxel px5301-t0 Firmware
Zyxel vmg4927-b50a
Zyxel vmg4927-b50a Firmware
Zyxel wx5610-b0
Zyxel wx5610-b0 Firmware

Tue, 24 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 24 Feb 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Zyxel
Zyxel ex3510-b0 Firmware
Vendors & Products Zyxel
Zyxel ex3510-b0 Firmware

Tue, 24 Feb 2026 03:00:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published:

Updated: 2026-02-26T14:44:10.318Z

Reserved: 2025-12-03T05:28:13.264Z

Link: CVE-2025-13942

cve-icon Vulnrichment

Updated: 2026-02-24T16:04:51.639Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-24T03:16:00.223

Modified: 2026-02-25T18:13:10.563

Link: CVE-2025-13942

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-24T09:53:14Z

Weaknesses