PT-2026-21644 · Zyxel · Zyxel Dx3301-T0

Published

2026-02-24

·

Updated

2026-03-01

·

CVE-2025-13943

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0
Description A post-authentication command injection issue exists in the log file download function. This could allow an authenticated attacker to execute operating system (OS) commands on an affected device.
Recommendations Versions prior to 5.50(ABVY.7)C0 should be updated.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2026-03188
CVE-2025-13943

Affected Products

Zyxel Dx3301-T0