Zyxel Vulnerabilities Allow Remote Attackers to Execute Commands via Command Injection
Zyxel has issued important security updates addressing vulnerabilities in various products, including 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, Security Routers, and Wireless Extenders.
Zyxel has issued important security updates addressing vulnerabilities in various products, including 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, Security Routers, and Wireless Extenders.
The security flaws identified range from null pointer dereferences leading to Denial-of-Service (DoS) attacks to severe command injections that enable remote attackers to execute system commands.
CVE ID Severity Vulnerability Type Attack Vector Impact
CVE-2025-13942 Critical (CVSS 9.8) Command Injection Remote (UPnP) OS Command Execution
CVE-2025-13943 High Command Injection Authenticated User OS Command Execution
CVE-2026-1459 High (CVSS 7.2) Command Injection Authenticated Admin OS Command Execution
This issue involves a command injection vulnerability within the UPnP function of certain devices.
CVE-2025-11845 to 11848 Medium (CVSS 4.9) Null Pointer Dereference Authenticated Admin Denial-of-Service (DoS)
Notably, CVE-2025-13942, with a CVSS score of 9.8, poses significant risk. This issue involves a command injection vulnerability within the UPnP function of certain devices. Users who have manually enabled WAN access and the vulnerable UPnP function may be exposed to unauthenticated remote attacks.
Zyxel has addressed four null pointer dereference vulnerabilities (CVE-2025-11845 through CVE-2025-11848) in various CGI programs. These vulnerabilities, each with a CVSS score of 4.9, can be exploited by an authenticated attacker with admin privileges through specially crafted HTTP requests, resulting in a DoS condition.
By default, WAN access is disabled, mitigating these attacks unless user-configured passwords are compromised.
Zyxel has released firmware updates for most affected models. However, patches for CVE-2026-1459 will be available in March 2026. Users are advised to download the latest firmware from official support channels and ensure WAN access remains disabled to mitigate the risk of remote attacks.
End-users who obtained devices from their ISPs should contact their provider's support team for customized updates.
For more information, visit the Zyxel Security Advisory .
Based on reporting by GBHackers.
