Critical Zyxel router flaw exposed devices to remote attacks
ID: 7eee5eed-0d84-5b80-be12-1c014d8ec0c9
STIX ID: report--7eee5eed-0d84-5b80-be12-1c014d8ec0c9
Feed Name: Security Affairs
Threat Score
Zyxel addressed a critical UPnP command-injection vulnerability (CVE-2025-13942, CVSS 9.8) impacting multiple CPEs, Fiber ONTs, and wireless extenders that can enable remote OS command execution when WAN access and the vulnerable UPnP function are enabled; the vendor published advisories, disclosed related null-pointer and post-auth command-injection flaws, and plans firmware updates, and users are urged to update affected devices immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
