Gbhackers Zyxel Addresses Critical RCE Flaw in Multiple Router Models
Article Content
Browse articles
Zyxel has issued security updates for a critical remote command execution vulnerability, tracked as CVE-2025-13942, affecting various router models. The flaw exists in the UPnP function, allowing unauthenticated attackers to execute arbitrary OS commands on unpatched devices. Affected devices include Zyxel's 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, and wireless extenders.
Ask AI about this cluster
Answers cite the sources they use
Updated 212d ago How this analysis works
Timeline
2025-02-04
CVE-2024-40891 published
2026-02-24
CVE-2025-13942 published
2026-02-24
CVE-2025-13943 published
2026-02-24
CVE-2026-1459 published
2026-02-24
CVE-2025-40540 published
2026-02-25
Zyxel releases security updates for affected devices
More articles in this cluster (11)
Following this threat?
Track Zyxel and CVE-2024-40891 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Chinese Hackers Exploit Zyxel Switch Vulnerability CVE-2026-7273 A Chinese-speaking threat actor has exploited a stack-based buffer overflow vulnerability (CVE-2026-7273) in Zyxel GS1900 switches, compromising 996 devices across 48 countries since August 17, 2026. The vulnerability allows unauthenticated attackers to execute OS commands via crafted HTTP requests. Zyxel released…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…