Zyxel warns that more than a dozen routers could be affected by a critical RCE security flaw



  • Zyxel fixed seven flaws on multiple devices, including critical CVE-2025-13942 (9.8/10)
  • Command injection over UPnP could allow remote execution of operating system commands if WAN and UPnP access are enabled
  • Around 120,000 Zyxel devices are exposed to the Internet

Zyxel has confirmed that it recently fixed half a dozen vulnerabilities, including a critical issue that allowed threat actors to execute arbitrary commands remotely.

In a security advisory, Zyxel detailed how to patch a command injection vulnerability in the UPnP feature of certain firmware versions of 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONT, and Wireless Extenders. This vulnerability is tracked as CVE-2025-13942 and was assigned a severity score of 9.8/10 (critical).



Leave a Comment

Your email address will not be published. Required fields are marked *