cbcvebase.
CVE-2025-13943
published 2026-02-24

CVE-2025-13943: A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could…

PriorityP267high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.40%
69.3th percentile
A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device.

Affected

54 ranges· showing 25
VendorProductVersion rangeFixed in
zyxelam7510-00_firmware< 5.63\(acoe.0.1\)c05.63\(acoe.0.1\)c0
zyxelax7501-b1_firmware< 5.17\(abpc.7.1\)c05.17\(abpc.7.1\)c0
zyxeldm4200-b0_firmware< 5.17\(acbs.1.6\)c05.17\(acbs.1.6\)c0
zyxeldx3300-t0_firmware< 5.50\(abvy.7.1\)c05.50\(abvy.7.1\)c0
zyxeldx3300-t1_firmware< 5.50\(abvy.7.1\)c05.50\(abvy.7.1\)c0
zyxeldx3301-t0_firmware< 5.50\(abvy.7.1\)c05.50\(abvy.7.1\)c0
zyxeldx4510-b0_firmware< 5.17\(abyl.10.1\)c05.17\(abyl.10.1\)c0
zyxeldx4510-b1_firmware< 5.17\(abyl.10.1\)c05.17\(abyl.10.1\)c0
zyxeldx5401-b1_firmware< 5.17\(abyo.7.1\)c05.17\(abyo.7.1\)c0
zyxelee3301-00_firmware< 5.63\(acmu.2.1\)c05.63\(acmu.2.1\)c0
zyxelee5301-00_firmware< 5.63\(acld.2.1\)c05.63\(acld.2.1\)c0
zyxelee6510-10_firmware< 5.19\(acjq.4.1\)c05.19\(acjq.4.1\)c0
zyxelemg3525-t50b_firmware< 5.50\(abpm.9.7\)c05.50\(abpm.9.7\)c0
zyxelemg5523-t50b_firmware< 5.50\(abpm.9.7\)c05.50\(abpm.9.7\)c0
zyxelemg6726-b10a_firmware< 5.13\(abnp.8.2\)c15.13\(abnp.8.2\)c1
zyxelex2210-t0_firmware< 5.50\(acdi.2.3\)c05.50\(acdi.2.3\)c0
zyxelex3300-t0_firmware< 5.50\(abvy.7.1\)c05.50\(abvy.7.1\)c0
zyxelex3300-t1_firmware< 5.50\(abvy.7.1\)c05.50\(abvy.7.1\)c0
zyxelex3301-t0_firmware< 5.50\(abvy.7.1\)c05.50\(abvy.7.1\)c0
zyxelex3301-t0_firmware<= 5.50(ABVY.7)C0
zyxelex3500-t0_firmware< 5.44\(achr.5.1\)c05.44\(achr.5.1\)c0
zyxelex3501-t0_firmware< 5.44\(achr.5.1\)c05.44\(achr.5.1\)c0
zyxelex3510-b0_firmware< 5.17\(abup.15.2\)c05.17\(abup.15.2\)c0
zyxelex3510-b1_firmware< 5.17\(abup.15.2\)c05.17\(abup.15.2\)c0
zyxelex3600-t0_firmware< 5.70\(acif.2.1\)c05.70\(acif.2.1\)c0

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2025-13943 is a post-authentication command injection in the log file download function; monitor for authenticated HTTP requests to log download endpoints on Zyxel EX3301-T0 devices with anomalous OS command injection patterns (e.g., shell metacharacters in parameters)
  • Exploitation requires valid credentials; correlate successful authentication events on Zyxel EX3301-T0 devices followed immediately by log file download requests containing command injection payloads
  • ·Affected firmware is Zyxel EX3301-T0 versions through 5.50(ABVY.7)C0; devices running this firmware version or earlier are vulnerable and should be prioritized for patching
  • ·This is a post-authentication vulnerability, meaning an attacker must first obtain valid credentials before exploiting the log file download function; attack surface is reduced compared to unauthenticated flaws but remains high-severity
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.