PT-2025-47237 · Zyxel · Zyxel Dx3300-T0

CVE-2025-8693

·

Published

2025-11-18

·

Updated

2025-12-15

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zyxel DX3300-T0 firmware versions prior to 5.50(ABVY.6.3)C0
Description A post-authentication command injection issue exists in the priv parameter. Successful exploitation allows an authenticated attacker to execute operating system (OS) commands on an affected device. The vulnerability is present in the Zyxel DX3300-T0 firmware.
Recommendations Update Zyxel DX3300-T0 firmware to version 5.50(ABVY.6.3)C0 or later.

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15911
CVE-2025-8693

Affected Products

Zyxel Dx3300-T0