CVE-2025-13943Disclosure(zyxel / am7510-00)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch zyxel am7510-00 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • am7510-00
  • am7510-00_firmware
  • ax7501-b1
  • ax7501-b1_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 11 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • Peaked 5d ago at 5 mentions (2026-02-24); latest day: 1
  • 11 total mentions across 6 days

Affected systems

Vendors
Products
am7510-00am7510-00_firmwareax7501-b1ax7501-b1_firmwaredm4200-b0dm4200-b0_firmwaredx3300-t0dx3300-t0_firmwaredx3300-t1dx3300-t1_firmware

1 version affected across 104 products

Deep dive

Activity timeline11 mentions / 6d
01345Mentions · 2026-02-24: 5Mentions · 2026-02-25: 1Mentions · 2026-02-26: 1Mentions · 2026-02-27: 2Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1PoC Mentioned / Linked · 2026-02-24: 1Exploit Tool / Code · 2026-02-24: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-24: 4Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 102-2402-2502-2602-2702-2803-01
Signal classification3 categories
Disclosure
763.6%
Patch
327.3%
Exploit
19.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-245
Disclosure4Exploit1
2026-02-251
Patch1
2026-02-261
Patch1
2026-02-272
Disclosure1Patch1
2026-02-281
Disclosure1
2026-03-011
Disclosure1
Full discourse11 posts
  • Victor Fresk0@hacefresko
    Exploit

    Zyxel has published 2 CVEs for some vulns I found :D CVE-2025-13943: Authenticated command injection in log export CGI CVE-2025-13942: Unauthenticated command injection in UPnP daemon I will blog about this in the coming months. Meanwhile, exploits here: https://github.com/hacefresko/CVEs

    Post summary

    Zyxel disclosed two command injection CVEs, and exploit code is available on GitHub, with no mention of patches or active exploitation.

    115044132.5K
    907 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-13943: HIGH] Critical cyber security alert: Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 are vulnerable to command injection, enabling attackers to run OS commands.#cve,CVE-2025-13943,#cybersecurity https://cvefind.com/CVE-2025-13943

    Post summary

    The post alerts that Zyxel EX3301‑T0 firmware versions up to 5.50(ABVY.7)C0 are vulnerable to command injection, enabling attackers to execute OS commands.

    0000149
    584 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-13943 (CVSS:8.8, HIGH) is Analyzed. A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware ..https://nvd.nist.gov/vuln/detail/CVE-2025-13943 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces a high‑severity post‑authentication command injection flaw in Zyxel EX3301‑T0 firmware, with CVSS 8.8, but provides no PoC, exploit, or patch details.

    0000071
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-13943 (CVSS:8.8, HIGH) is Analyzed. A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware ..https://nvd.nist.gov/vuln/detail/CVE-2025-13943 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE‑2025‑13943, detailing a high‑severity post‑authentication command injection in Zyxel EX3301‑T0 firmware, but does not provide a PoC, exploit, or mitigation.

    0000083
    173 followersView on X
  • Eclypsium@eclypsium
    Patch

    Organizations using Zyxel products should prioritize installing the recommended patches and consider replacing any legacy devices that are no longer supported or have reached end-of-life status (CVE-2025-13943, CVE-2026-1459, CVE-2024-40891). https://hubs.ly/Q0451tTh0

    Post summary

    Zyxel recommends that organizations patch or replace affected devices to mitigate CVE-2025-13943, CVE-2026-1459, and CVE-2024-40891.

    00000175
    1.8K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Zyxel ❗ CVE-2026-1459 ❗ CVE-2025-13943 ❗ CVE-2025-13942 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-zyxel-2/ https://t.co/Mm5XqgBCoc

    Post summary

    The tweet announces three CVE identifiers for Zyxel products and links to additional information, indicating a new vulnerability disclosure.

    00000102
    6.6K followersView on X
  • Cyber News Live@cybernewslive
    Patch

    Zyxel has released updates for over a dozen router models to fix a critical vulnerability, CVE-2025-13942, allowing remote command execution. While exploitation requires specific settings to be enabled, users should install the patches. Zyxel also addressed two high-severity flaws, CVE-2025-13943 and CVE-2026-1459, which require compromised credentials. If your Zyxel router model is end-of-life, Zyxel advises replacing it since no further patches will be issued. ⚠️ #CyberNewsLive https://bleepingcomputer.com/news/security/zyxel-warns-of-critical-rce-flaw-affecting-over-a-dozen-routers/

    Post summary

    Zyxel has issued patches for CVE‑2025‑13942 and related high‑severity flaws, urging users to update or replace end‑of‑life routers to mitigate remote command execution risks.

    0000052
    1.5K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Critical Zyxel router UPnP command-injection flaw enables unauth remote OS command execution Zyxel patched CVE-2025-13942 (CVSS 9.8), a UPnP command-injection bug affecting 4G/5G CPE, DSL/Ethernet CPE, Fiber ONTs, and wireless extenders that can allow unauth attackers to run OS commands via crafted UPnP SOAP requests (only if WAN access and UPnP are enabled). Zyxel also disclosed additional DoS and post-auth command-injection issues (incl. CVE-2026-1459 / CVE-2025-13943), urging immediate firmware updates to prevent device takeover. 🎯 Target: Global/Telecom & Home Router Users #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://securityaffairs.com/188501/security/critical-zyxel-router-flaw-exposed-devices-to-remote-attacks.html

    Post summary

    Zyxel disclosed a critical UPnP command‑injection flaw (CVE-2025-13942) that permits unauthenticated remote OS command execution, and urged users to apply firmware updates to mitigate the risk.

    0000070
    214 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-13943 A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an… https://www.cve.org/CVERecord?id=CVE-2025-13943

    Post summary

    The text announces a post‑authentication command injection vulnerability in Zyxel EX3301‑T0 firmware, providing technical details but no PoC, exploit, or patch information.

    0000082
    56.5K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting Zyxel EX3301-T0 (CVE-2025-13943) https://vuldb.com/?id.347464

    Post summary

    A new vulnerability (CVE-2025-13943) affecting Zyxel EX3301-T0 has an increased severity, as reported on vuldb.com.

    0000075
    2.1K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2025-13943 - Zyxel - EX3301-T0 firmware - https://www.redpacketsecurity.com/cve-alert-cve-2025-13943-zyxel-ex3301-t0-firmware/ #OSINT #ThreatIntel #CyberSecurity #cve-2025-13943 #zyxel #ex3301-t0-firmware

    Post summary

    A CVE alert for CVE-2025-13943 affecting Zyxel EX3301‑T0 firmware was posted with a link to a security site, but no further details are provided in the text.

    0000095
    3.5K followersView on X
CPE platform detail104 entries

104 of 104 entries

PartVendorProductVersionTarget SWTarget HW
HWzyxelam7510-00---
OSzyxelam7510-00_firmware---
HWzyxelax7501-b1---
OSzyxelax7501-b1_firmware---
HWzyxeldm4200-b0---
OSzyxeldm4200-b0_firmware---
HWzyxeldx3300-t0---
OSzyxeldx3300-t0_firmware---
HWzyxeldx3300-t1---
OSzyxeldx3300-t1_firmware---
HWzyxeldx3301-t0---
OSzyxeldx3301-t0_firmware---
HWzyxeldx4510-b0---
OSzyxeldx4510-b0_firmware---
HWzyxeldx4510-b1---
OSzyxeldx4510-b1_firmware---
HWzyxeldx5401-b1---
OSzyxeldx5401-b1_firmware---
HWzyxelee3301-00---
OSzyxelee3301-00_firmware---
HWzyxelee5301-00---
OSzyxelee5301-00_firmware---
HWzyxelee6510-10---
OSzyxelee6510-10_firmware---
HWzyxelemg3525-t50b---
OSzyxelemg3525-t50b_firmware---
HWzyxelemg5523-t50b---
OSzyxelemg5523-t50b_firmware---
HWzyxelemg6726-b10a---
OSzyxelemg6726-b10a_firmware---
HWzyxelex2210-t0---
OSzyxelex2210-t0_firmware---
HWzyxelex3300-t0---
OSzyxelex3300-t0_firmware---
HWzyxelex3300-t1---
OSzyxelex3300-t1_firmware---
HWzyxelex3301-t0---
OSzyxelex3301-t0_firmware---
HWzyxelex3500-t0---
OSzyxelex3500-t0_firmware---
HWzyxelex3501-t0---
OSzyxelex3501-t0_firmware---
HWzyxelex3510-b0---
OSzyxelex3510-b0_firmware---
HWzyxelex3510-b1---
OSzyxelex3510-b1_firmware---
HWzyxelex3600-t0---
OSzyxelex3600-t0_firmware---
HWzyxelex5401-b1---
OSzyxelex5401-b1_firmware---
HWzyxelex5510-b0---
OSzyxelex5510-b0_firmware---
HWzyxelex5512-t0---
OSzyxelex5512-t0_firmware---
HWzyxelex5601-t0---
OSzyxelex5601-t0_firmware---
HWzyxelex5601-t1---
OSzyxelex5601-t1_firmware---
HWzyxelex7501-b0---
OSzyxelex7501-b0_firmware---
HWzyxelex7710-b0---
OSzyxelex7710-b0_firmware---
HWzyxelgm4100-b0---
OSzyxelgm4100-b0_firmware---
HWzyxelpe3301-00---
OSzyxelpe3301-00_firmware---
HWzyxelpe5301-01---
OSzyxelpe5301-01_firmware---
HWzyxelpm3100-t0---
OSzyxelpm3100-t0_firmware---
HWzyxelpm5100-t0---
OSzyxelpm5100-t0_firmware---
HWzyxelpm5100-t1---
OSzyxelpm5100-t1_firmware---
HWzyxelpm7300-t0---
OSzyxelpm7300-t0_firmware---
HWzyxelpm7500-00---
OSzyxelpm7500-00_firmware---
HWzyxelpx3321-t1---
OSzyxelpx3321-t1_firmware---
HWzyxelpx5301-t0---
OSzyxelpx5301-t0_firmware---
HWzyxelvmg3625-t50b---
OSzyxelvmg3625-t50b_firmware---
HWzyxelvmg4005-b50a---
OSzyxelvmg4005-b50a_firmware---
HWzyxelvmg4005-b60a---
OSzyxelvmg4005-b60a_firmware---
HWzyxelvmg4927-b50a---
OSzyxelvmg4927-b50a_firmware---
HWzyxelvmg8623-t50b---
OSzyxelvmg8623-t50b_firmware---
HWzyxelwe3300-00---
OSzyxelwe3300-00_firmware---
HWzyxelwe4600-00---
OSzyxelwe4600-00_firmware---
HWzyxelwx3100-t0---
OSzyxelwx3100-t0_firmware---
HWzyxelwx3401-b1---
OSzyxelwx3401-b1_firmware---
HWzyxelwx5600-t0---
OSzyxelwx5600-t0_firmware---
HWzyxelwx5610-b0---
OSzyxelwx5610-b0_firmware---

Explore more