Post-Authentication Command Injection in Zyxel EX3301-T0 Firmware
CVE-2025-13943
8.8HIGH
What is CVE-2025-13943?
A post-authentication command injection vulnerability exists in the log file download function of Zyxel EX3301-T0 firmware. An authenticated attacker could exploit this flaw to execute arbitrary operating system commands on the affected device, potentially leading to unauthorized access and manipulation of system resources. This security risk emphasizes the need for timely updates and patches to ensure firmware integrity and protect against misuse.
Affected Version(s)
EX3301-T0 firmware <= 5.50(ABVY.7)C0