Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical Zyxel Vulnerabilities Exposes Routers to Remote Command Injection

Zyxel Vulnerabilities Critical firmware updates have been released to address multiple serious vulnerabilities in networking devices, including 4G LTE/5G NR CPEs, DSL/Ethernet CPEs, Fiber ONTs, Security Routers, and Wireless Extenders.

Zyxel Vulnerabilities Critical firmware updates have been released to address multiple serious vulnerabilities in networking devices, including 4G LTE/5G NR CPEs, DSL/Ethernet CPEs, Fiber ONTs, Security Routers, and Wireless Extenders.

These flaws expose affected routers to remote command injection and denial-of-service (DoS) attacks .

The security advisory highlights seven distinct vulnerabilities discovered by security researchers Tiantai Zhang, Víctor Fresco, and Watchful IP.

The most critical is an unauthenticated command injection flaw , alongside several post-authentication risks and null pointer dereferences.

The most severe threat stems from CVE-2025-13942 (CVSS 9.8), which allows remote code execution (RCE) without requiring user authentication.

If a malicious actor sends a specially crafted UPnP request, they can completely compromise the device’s operating system.

These flaws expose affected routers to remote command injection and denial-of-service (DoS) attacks .
Lucas Gallagher · Thehackingpost

Fortunately, a built-in mitigating factor exists: WAN access is restricted by default on all affected Zyxel devices.

CVE IDVulnerability TypeImpact & Attack VectorCVE-2025-13942Command Injection (UPnP)Remote attackers can execute arbitrary OS commands via crafted UPnP SOAP requests.CVE-2025-13943Post-Auth Command InjectionAuthenticated users can run OS commands through the log file download feature.CVE-2026-1459Post-Auth Command InjectionAuthenticated admins can execute OS commands via TR-369 certificate download CGI.CVE-2025-11845Null Pointer DereferenceCrafted HTTP requests to certificate downloader CGI trigger device DoS.CVE-2025-11846Null Pointer DereferenceMalformed HTTP requests to account settings CGI cause DoS.CVE-2025-11847Null Pointer DereferenceMalformed HTTP requests to IP settings CGI cause DoS.CVE-2025-11848Null Pointer DereferenceCrafted requests to Wake-on-LAN CGI can crash the device (DoS). An attack can only succeed if a user has manually enabled both WAN access and the vulnerable UPnP function .

Similarly, the DoS vulnerabilities and post-authentication command injection require compromised administrator passwords to be exploited.

Dozens of specific models are impacted, including popular enterprise and consumer lines. Below is a snapshot of devices vulnerable to the critical CVE-2025-13942 flaw:

Advertisement

Product CategoryAffected ModelAffected VersionPatch Version4G LTE/5G NR CPENebula NR71011.16(ACCC.1)C0 & earlier1.16(ACCC.1)V0DSL/Ethernet CPEDX4510-B05.17(ABYL.10)C0 & earlier5.17(ABYL.10.1)C0Fiber ONTsPX5301-T05.44(ACKB.0.5)C0 & earlier5.44(ACKB.0.6)C0Wireless ExtendersWX5610-B05.18(ACGJ.0.4)C0 & earlier5.18(ACGJ.0.5)C0 Zyxel has released firmware updates for the vast majority of affected products.

However, specific DSL/Ethernet CPE models affected by CVE-2026-1459 (such as the DX5401-B1 and EMG3525-T50B) are scheduled to receive official patches in March 2026.​

To maintain optimal network protection, administrators must take immediate action:

Mitigation StepDescriptionApply Firmware UpdatesDownload and install the latest firmware from the official support portal or community forum.Restrict WAN AccessDisable WAN access and UPnP on external interfaces unless absolutely necessary.Update CredentialsChange default or weak passwords to prevent post-authentication exploitation.Contact ISPsFor ISP-provided devices, contact your provider for custom firmware updates. Follow us on Google News , LinkedIn , and X for daily cybersecurity updates. Contact us to feature your stories.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories