Zyxel warns that more than a dozen routers could be affected by critical RCE security flaw


  • Zyxel fixed seven flaws on several devices, including critical CVE-2025-13942 (9.8/10)
  • Command injection via UPnP could enable remote OS command execution if WAN access and UPnP are enabled
  • Around 120,000 Zyxel devices are exposed to the Internet

Zyxel confirmed that it recently patched half a dozen vulnerabilities, including a critical severity issue that allowed malicious actors to execute arbitrary commands remotely.

In a security advisory, Zyxel detailed the fix for a command injection vulnerability in the UPnP feature of certain 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONT, and Wireless Extenders firmware versions. This vulnerability is tracked as CVE-2025-13942 and received a severity score of 9.8/10 (critical).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top