PT-2026-21644 · Zyxel · Zyxel Dx3301-T0

CVE-2025-13943

·

Published

2026-02-24

·

Updated

2026-03-01

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0
Description A post-authentication command injection issue exists in the log file download function. This could allow an authenticated attacker to execute operating system (OS) commands on an affected device.
Recommendations Versions prior to 5.50(ABVY.7)C0 should be updated.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03188
CVE-2025-13943

Affected Products

Zyxel Dx3301-T0