CVE-2025-13943
published 2026-02-24CVE-2025-13943: A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could…
PriorityP267high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.40%
69.6th percentile
A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device.
Affected
54 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | am7510-00_firmware | < 5.63\(acoe.0.1\)c0 | 5.63\(acoe.0.1\)c0 |
| zyxel | ax7501-b1_firmware | < 5.17\(abpc.7.1\)c0 | 5.17\(abpc.7.1\)c0 |
| zyxel | dm4200-b0_firmware | < 5.17\(acbs.1.6\)c0 | 5.17\(acbs.1.6\)c0 |
| zyxel | dx3300-t0_firmware | < 5.50\(abvy.7.1\)c0 | 5.50\(abvy.7.1\)c0 |
| zyxel | dx3300-t1_firmware | < 5.50\(abvy.7.1\)c0 | 5.50\(abvy.7.1\)c0 |
| zyxel | dx3301-t0_firmware | < 5.50\(abvy.7.1\)c0 | 5.50\(abvy.7.1\)c0 |
| zyxel | dx4510-b0_firmware | < 5.17\(abyl.10.1\)c0 | 5.17\(abyl.10.1\)c0 |
| zyxel | dx4510-b1_firmware | < 5.17\(abyl.10.1\)c0 | 5.17\(abyl.10.1\)c0 |
| zyxel | dx5401-b1_firmware | < 5.17\(abyo.7.1\)c0 | 5.17\(abyo.7.1\)c0 |
| zyxel | ee3301-00_firmware | < 5.63\(acmu.2.1\)c0 | 5.63\(acmu.2.1\)c0 |
| zyxel | ee5301-00_firmware | < 5.63\(acld.2.1\)c0 | 5.63\(acld.2.1\)c0 |
| zyxel | ee6510-10_firmware | < 5.19\(acjq.4.1\)c0 | 5.19\(acjq.4.1\)c0 |
| zyxel | emg3525-t50b_firmware | < 5.50\(abpm.9.7\)c0 | 5.50\(abpm.9.7\)c0 |
| zyxel | emg5523-t50b_firmware | < 5.50\(abpm.9.7\)c0 | 5.50\(abpm.9.7\)c0 |
| zyxel | emg6726-b10a_firmware | < 5.13\(abnp.8.2\)c1 | 5.13\(abnp.8.2\)c1 |
| zyxel | ex2210-t0_firmware | < 5.50\(acdi.2.3\)c0 | 5.50\(acdi.2.3\)c0 |
| zyxel | ex3300-t0_firmware | < 5.50\(abvy.7.1\)c0 | 5.50\(abvy.7.1\)c0 |
| zyxel | ex3300-t1_firmware | < 5.50\(abvy.7.1\)c0 | 5.50\(abvy.7.1\)c0 |
| zyxel | ex3301-t0_firmware | < 5.50\(abvy.7.1\)c0 | 5.50\(abvy.7.1\)c0 |
| zyxel | ex3301-t0_firmware | <= 5.50(ABVY.7)C0 | — |
| zyxel | ex3500-t0_firmware | < 5.44\(achr.5.1\)c0 | 5.44\(achr.5.1\)c0 |
| zyxel | ex3501-t0_firmware | < 5.44\(achr.5.1\)c0 | 5.44\(achr.5.1\)c0 |
| zyxel | ex3510-b0_firmware | < 5.17\(abup.15.2\)c0 | 5.17\(abup.15.2\)c0 |
| zyxel | ex3510-b1_firmware | < 5.17\(abup.15.2\)c0 | 5.17\(abup.15.2\)c0 |
| zyxel | ex3600-t0_firmware | < 5.70\(acif.2.1\)c0 | 5.70\(acif.2.1\)c0 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-13943 is a post-authentication command injection in the log file download function; monitor for authenticated HTTP requests to log download endpoints on Zyxel EX3301-T0 devices with anomalous OS command injection patterns (e.g., shell metacharacters in parameters) ↗
- →Exploitation requires valid credentials; correlate successful authentication events on Zyxel EX3301-T0 devices followed immediately by log file download requests containing command injection payloads ↗
- ·Affected firmware is Zyxel EX3301-T0 versions through 5.50(ABVY.7)C0; devices running this firmware version or earlier are vulnerable and should be prioritized for patching ↗
- ·This is a post-authentication vulnerability, meaning an attacker must first obtain valid credentials before exploiting the log file download function; attack surface is reduced compared to unauthenticated flaws but remains high-severity ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
2026-02-24
Published