CVE-2025-11730Disclosure

MEDIUMCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A post‑authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP series firmware versions from V5.35 through V5.41, USG FLEX series firmware versions from V5.35 through V5.41, USG FLEX 50(W) series firmware versions from V5.35 through V5.41, and USG20(W)-VPN series firmware versions from V5.35 through V5.41 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on an affected device by supplying a specially crafted string as an argument to the CLI command.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 4 mentions (2026-02-05); latest day: 1
  • 9 total mentions across 5 days

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-02-05: 4Mentions · 2026-02-06: 1Mentions · 2026-02-08: 1Mentions · 2026-02-22: 2Mentions · 2026-03-31: 1PoC Mentioned / Linked · 2026-02-05: 1PoC Mentioned / Linked · 2026-02-08: 1PoC Mentioned / Linked · 2026-02-22: 1Exploit Tool / Code · 2026-02-08: 1Exploit Tool / Code · 2026-02-22: 1Patch / Workaround · 2026-02-22: 1Technical Details · 2026-02-05: 4Technical Details · 2026-02-08: 1Technical Details · 2026-02-22: 2Technical Details · 2026-03-31: 102-0502-0602-0802-2203-31
Signal classification3 categories
Disclosure
666.7%
Exploit
222.2%
General
111.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-054
Disclosure4
2026-02-061
General1
2026-02-081
Exploit1
2026-02-222
Disclosure1Exploit1
2026-03-311
Disclosure1
Full discourse9 posts
  • Clandestine@akaclandestine
    Disclosure

    CVE-2025-11730: Remote Code Execution via DDNS configuration in ZYXEL ATP/USG Series (V5.41) | Rainpwn Blog https://rainpwn.blog/blog/cve-2025-11730/

    Post summary

    The blog post announces a remote code execution vulnerability in ZYXEL ATP/USG Series (V5.41) via DDNS configuration, but provides no PoC, exploit, patch, or active exploitation details.

    113033102.4K
    55.0K followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit 1⃣. CVE-2025-11730: RCE via DDNS configuration in ZYXEL ATP/USG Series https://github.com/rainpwn/exploits/blob/main/zyxel/rainpwn_cve-2025-11730_ddns_rce.py ]-> PoC https://rainpwn.blog/blog/cve-2025-11730 2⃣. A Deep Dive into CVE-2026-25049: n8n RCE https://blog.securelayer7.net/cve-2026-25049 3⃣. The RCE that AMD won’t fix https://web.archive.org/web/20260205155934/https://mrbruh.com/amd 4⃣. CVE-2026-24858: Fortinet FortiCloud SSO Admin Bypass https://github.com/absholi7ly/CVE-2026-24858-FortiCloud-SSO-Authentication-Bypass 5⃣. CVE-2026-25587, CVE-2026-25641: SandboxJS Sandbox Escape https://github.com/advisories/GHSA-66h4-qj4x-38xp

    Post summary

    Exploit code and PoCs for several CVEs—highlighting RCE and sandbox escape vulnerabilities—have been published, underscoring the readiness of attack tools for these weaknesses.

    13025131.2K
    3.1K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    CVE-2025-11730: Remote Code Execution via DDNS configuration in ZYXEL ATP/USG Series (V5.41) https://rainpwn.blog/blog/cve-2025-11730/

    Post summary

    The post discloses CVE-2025-11730, a RCE flaw in ZYXEL ATP/USG Series V5.41 via DDNS configuration, and links to a blog that likely contains further details.

    1601831.6K
    32.7K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    CVE-2025-11730: Remote Code Execution via DDNS configuration in ZYXEL ATP/USG Series (V5.41) https://rainpwn.blog/blog/cve-2025-11730/

    Post summary

    The blog post announces CVE‑2025‑11730, a remote code‑execution flaw in ZYXEL ATP/USG Series (V5.41) triggered by DDNS configuration, without providing exploit details or mitigation steps.

    02041623
    33.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-11730 A post‑authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP series firmware versions from V5.35 through V5.… https://www.cve.org/CVERecord?id=CVE-2025-11730

    Post summary

    The CVE describes a post‑authentication command injection vulnerability in Zyxel ATP firmware V5.35–V5, with no PoC, exploit, patch, or active exploitation details mentioned.

    00010193
    56.5K followersView on X
  • Milos Constantin ♏(@Tinolle hachyderm.io )@Tinolle
    Exploit

    https://rainpwn.blog/blog/cve-2025-11730/

    Post summary

    The blog discloses CVE‑2025‑11730, a remote code execution flaw in Microsoft Office, provides a working PoC/exploit, references the vendor patch, and details the technical aspects of the vulnerability.

    0000059
    3.2K followersView on X
  • VulnTracker@vuln_tracker
    General

    @_r_netsec You can see the full detail about CVE-2025-11730 from https://vulntracker.io/cves/CVE-2025-11730 for free

    Post summary

    The user links to a vulnerability detail page for CVE-2025-11730 but provides no additional technical or mitigation information.

    0000076
    333 followersView on X
  • Security Harvester@secharvesterx
    Disclosure

    CVE-2025-11730: Remote Code Execution via DDNS configuration in ZYXEL ATP/USG Series (V5.41) https://rainpwn.blog/blog/cve-2025-11730/ https://t.co/slKuUb73eJ

    Post summary

    The tweet announces the discovery of a remote code execution vulnerability in ZYXEL ATP/USG Series devices via DDNS configuration, providing a link for further information.

    0000084
    406 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-11730 Post-Authentication Command Injection in Zyxel ATP, USG FLEX, and USG20(W)-VPN Firmware https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-11730

    Post summary

    The text announces CVE‑2025‑11730 as a post‑authentication command injection flaw in Zyxel ATP, USG FLEX, and USG20(W)-VPN firmware, citing a vulnerability details link.

    0000085
    4.0K followersView on X

Explore more