Cyber News Live[verified]@cybernewslivePatch
Zyxel has issued patches for CVE‑2025‑13942 and related high‑severity flaws, urging users to update or replace end‑of‑life routers to mitigate remote command execution risks.
ThreatSynop[verified]@ThreatSynopPatch
Zyxel disclosed a critical UPnP command‑injection flaw (CVE-2025-13942) that permits unauthenticated remote OS command execution, and urged users to apply firmware updates to mitigate the risk.
Victor Fresk0@hacefreskoExploit
Zyxel disclosed two command injection CVEs, and exploit code is available on GitHub, with no mention of patches or active exploitation.
CVEFind.com@CveFindComDisclosure
The post alerts that Zyxel EX3301‑T0 firmware versions up to 5.50(ABVY.7)C0 are vulnerable to command injection, enabling attackers to execute OS commands.
CRAC Learning - Tech@cracbotDisclosure
The post announces a high‑severity post‑authentication command injection flaw in Zyxel EX3301‑T0 firmware, with CVSS 8.8, but provides no PoC, exploit, or patch details.
CRAC Learning - Tech@cracbotDisclosure
The tweet announces CVE‑2025‑13943, detailing a high‑severity post‑authentication command injection in Zyxel EX3301‑T0 firmware, but does not provide a PoC, exploit, or mitigation.
Eclypsium@eclypsiumPatch
Zyxel recommends that organizations patch or replace affected devices to mitigate CVE-2025-13943, CVE-2026-1459, and CVE-2024-40891.
CERT-PY@CERTpyDisclosure
The tweet announces three CVE identifiers for Zyxel products and links to additional information, indicating a new vulnerability disclosure.