Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Zyxel Vulnerabilities Allow Remote Attackers to Execute Commands via Command Injection

Zyxel has issued important security updates addressing vulnerabilities in various products, including 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, Security Routers, and Wireless Extenders.

Zyxel has issued important security updates addressing vulnerabilities in various products, including 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, Security Routers, and Wireless Extenders.

The security flaws identified range from null pointer dereferences leading to Denial-of-Service (DoS) attacks to severe command injections that enable remote attackers to execute system commands.

CVE ID Severity Vulnerability Type Attack Vector Impact

CVE-2025-13942 Critical (CVSS 9.8) Command Injection Remote (UPnP) OS Command Execution

CVE-2025-13943 High Command Injection Authenticated User OS Command Execution

CVE-2026-1459 High (CVSS 7.2) Command Injection Authenticated Admin OS Command Execution

This issue involves a command injection vulnerability within the UPnP function of certain devices.
Mark Jensen · Thehackingpost

CVE-2025-11845 to 11848 Medium (CVSS 4.9) Null Pointer Dereference Authenticated Admin Denial-of-Service (DoS)

Notably, CVE-2025-13942, with a CVSS score of 9.8, poses significant risk. This issue involves a command injection vulnerability within the UPnP function of certain devices. Users who have manually enabled WAN access and the vulnerable UPnP function may be exposed to unauthenticated remote attacks.

Zyxel has addressed four null pointer dereference vulnerabilities (CVE-2025-11845 through CVE-2025-11848) in various CGI programs. These vulnerabilities, each with a CVSS score of 4.9, can be exploited by an authenticated attacker with admin privileges through specially crafted HTTP requests, resulting in a DoS condition.

By default, WAN access is disabled, mitigating these attacks unless user-configured passwords are compromised.

Advertisement

Zyxel has released firmware updates for most affected models. However, patches for CVE-2026-1459 will be available in March 2026. Users are advised to download the latest firmware from official support channels and ensure WAN access remains disabled to mitigate the risk of remote attacks.

End-users who obtained devices from their ISPs should contact their provider's support team for customized updates.

For more information, visit the Zyxel Security Advisory .

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories