CVE-2025-11730
7.2Zyxel · ATP, USG FLEX, and USG20-VPN series firmware
A command injection vulnerability in the Zyxel firmware DDNS configuration CLI allows authenticated administrators to execute arbitrary OS commands.
Executive summary
A post-authentication command injection vulnerability in Zyxel networking devices poses a severe risk of full system compromise for affected ATP and USG series appliances.
Vulnerability
This is a command injection vulnerability (CWE-78) triggered by supplying a malicious string to the Dynamic DNS configuration CLI command. The flaw requires the attacker to have already obtained administrative-level authentication to the device.
Business impact
The ability to execute arbitrary OS commands on network appliances allows an attacker to gain full control over the gateway, potentially leading to data exfiltration, lateral movement, or complete disruption of network services. With a CVSS score of 7.2, this high-severity flaw represents a significant threat to internal network integrity. Organizations must prioritize securing administrative credentials to prevent exploitation of this vector.
Remediation
Immediate Action: Audit all administrative access to affected Zyxel devices and apply vendor-supplied firmware updates as soon as they are released to patch the CLI command validation logic.
Proactive Monitoring: Review system and configuration logs for irregular CLI activity or unexpected command execution patterns associated with the DDNS settings.
Compensating Controls: Restrict access to the device management interface by limiting administrative access to trusted management subnets or via VPN to reduce the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for complete device takeover, administrators should verify their current firmware versions immediately. If running versions between V5.35 and V5.41, ensure that management interfaces are strictly firewalled from the public internet and limit administrative access to only authorized personnel until the vendor patch is deployed.