Description
A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.
Published: 2026-02-24
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 25 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Zyxel dx4510-b0
Zyxel dx4510-b0 Firmware
Zyxel dx4510-b1
Zyxel dx4510-b1 Firmware
Zyxel ee6510-10
Zyxel ee6510-10 Firmware
Zyxel emg6726-b10a
Zyxel emg6726-b10a Firmware
Zyxel ex2210-t0
Zyxel ex2210-t0 Firmware
Zyxel ex3510-b0
Zyxel ex3510-b1
Zyxel ex3510-b1 Firmware
Zyxel ex5510-b0
Zyxel ex5510-b0 Firmware
Zyxel ex5512-t0
Zyxel ex5512-t0 Firmware
Zyxel ex7710-b0
Zyxel ex7710-b0 Firmware
Zyxel lte3301-plus
Zyxel lte3301-plus Firmware
Zyxel nebula Lte3301-plus
Zyxel nebula Lte3301-plus Firmware
Zyxel nebula Nr7101
Zyxel nebula Nr7101 Firmware
Zyxel nr7101
Zyxel nr7101 Firmware
Zyxel px3321-t1
Zyxel px3321-t1 Firmware
Zyxel px5301-t0
Zyxel px5301-t0 Firmware
Zyxel vmg4927-b50a
Zyxel vmg4927-b50a Firmware
Zyxel wx5610-b0
Zyxel wx5610-b0 Firmware
CPEs cpe:2.3:h:zyxel:dx4510-b0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:dx4510-b1:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ee6510-10:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:emg6726-b10a:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ex2210-t0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ex3510-b0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ex3510-b1:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ex5510-b0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ex5512-t0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:ex7710-b0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:lte3301-plus:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:nebula_lte3301-plus:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:nebula_nr7101:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:nr7101:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:px3321-t1:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:px5301-t0:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg4927-b50a:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:wx5610-b0:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:dx4510-b0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:dx4510-b1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ee6510-10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:emg6726-b10a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ex2210-t0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ex3510-b0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ex3510-b1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ex5510-b0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ex5512-t0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:ex7710-b0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:lte3301-plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nebula_lte3301-plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nebula_nr7101_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nr7101_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:px3321-t1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:px5301-t0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg4927-b50a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:wx5610-b0_firmware:*:*:*:*:*:*:*:*
Vendors & Products Zyxel dx4510-b0
Zyxel dx4510-b0 Firmware
Zyxel dx4510-b1
Zyxel dx4510-b1 Firmware
Zyxel ee6510-10
Zyxel ee6510-10 Firmware
Zyxel emg6726-b10a
Zyxel emg6726-b10a Firmware
Zyxel ex2210-t0
Zyxel ex2210-t0 Firmware
Zyxel ex3510-b0
Zyxel ex3510-b1
Zyxel ex3510-b1 Firmware
Zyxel ex5510-b0
Zyxel ex5510-b0 Firmware
Zyxel ex5512-t0
Zyxel ex5512-t0 Firmware
Zyxel ex7710-b0
Zyxel ex7710-b0 Firmware
Zyxel lte3301-plus
Zyxel lte3301-plus Firmware
Zyxel nebula Lte3301-plus
Zyxel nebula Lte3301-plus Firmware
Zyxel nebula Nr7101
Zyxel nebula Nr7101 Firmware
Zyxel nr7101
Zyxel nr7101 Firmware
Zyxel px3321-t1
Zyxel px3321-t1 Firmware
Zyxel px5301-t0
Zyxel px5301-t0 Firmware
Zyxel vmg4927-b50a
Zyxel vmg4927-b50a Firmware
Zyxel wx5610-b0
Zyxel wx5610-b0 Firmware

Tue, 24 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 24 Feb 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Zyxel
Zyxel ex3510-b0 Firmware
Vendors & Products Zyxel
Zyxel ex3510-b0 Firmware

Tue, 24 Feb 2026 03:00:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zyxel Dx4510-b0 Dx4510-b0 Firmware Dx4510-b1 Dx4510-b1 Firmware Ee6510-10 Ee6510-10 Firmware Emg6726-b10a Emg6726-b10a Firmware Ex2210-t0 Ex2210-t0 Firmware Ex3510-b0 Ex3510-b0 Firmware Ex3510-b1 Ex3510-b1 Firmware Ex5510-b0 Ex5510-b0 Firmware Ex5512-t0 Ex5512-t0 Firmware Ex7710-b0 Ex7710-b0 Firmware Lte3301-plus Lte3301-plus Firmware Nebula Lte3301-plus Nebula Lte3301-plus Firmware Nebula Nr7101 Nebula Nr7101 Firmware Nr7101 Nr7101 Firmware Px3321-t1 Px3321-t1 Firmware Px5301-t0 Px5301-t0 Firmware Vmg4927-b50a Vmg4927-b50a Firmware Wx5610-b0 Wx5610-b0 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published:

Updated: 2026-02-26T14:44:10.318Z

Reserved: 2025-12-03T05:28:13.264Z

Link: CVE-2025-13942

cve-icon Vulnrichment

Updated: 2026-02-24T16:04:51.639Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-24T03:16:00.223

Modified: 2026-02-25T18:13:10.563

Link: CVE-2025-13942

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-24T09:53:14Z

Weaknesses