CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Critical RCE flaw in Zyxel routers allows remote command execution

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Zyxel has released security updates to address a critical command injection vulnerability (CVE-2025-13942) affecting over a dozen router models. The flaw allows unauthenticated attackers to execute OS commands via maliciously crafted UPnP SOAP requests. Successful exploitation requires both UPnP and WAN access to be enabled, with WAN access disabled by default. Zyxel also patched two high-severity post-authentication command-injection vulnerabilities (CVE-2025-13943 and CVE-2026-1459). Zyxel devices are frequently targeted in attacks due to their widespread use by internet service providers. The U.S. CISA is tracking 12 actively exploited Zyxel vulnerabilities. Additionally, Zyxel has no plans to patch two zero-day vulnerabilities (CVE-2024-40891 and CVE-2024-40891) affecting end-of-life routers, advising users to replace them with newer models.

Timeline

  1. 25.02.2026 14:53 1 articles · 2h ago

    Zyxel releases updates for critical RCE flaw in routers

    Zyxel has released security updates to address a critical command injection vulnerability (CVE-2025-13942) affecting over a dozen router models. The flaw allows unauthenticated attackers to execute OS commands via maliciously crafted UPnP SOAP requests. Successful exploitation requires both UPnP and WAN access to be enabled, with WAN access disabled by default. Zyxel also patched two high-severity post-authentication command-injection vulnerabilities (CVE-2025-13943 and CVE-2026-1459).

    Show sources

Information Snippets