CVE-2025-13943
8.8Zyxel · EX3301-T0
A post-authentication OS command injection vulnerability exists in the log file download function of Zyxel EX3301-T0 firmware, allowing authenticated attackers to execute arbitrary system commands.
Executive summary
Zyxel EX3301-T0 firmware contains a command injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands, posing a high risk to device integrity.
Vulnerability
This is an OS command injection vulnerability (CWE-78) triggered via the log file download function. The vulnerability requires the attacker to have authenticated access to the device, after which they can inject malicious commands into the system.
Business impact
Successful exploitation allows an authenticated attacker to achieve full command execution on the target device. This level of access can lead to complete device compromise, lateral movement within the network, or the installation of persistent malicious payloads. With a CVSS score of 8.8, this vulnerability is considered high severity due to the potential for total loss of confidentiality, integrity, and availability.
Remediation
Immediate Action: Administrators should check the official Zyxel support portal for the latest firmware release and apply the update immediately. If a patch is not yet available, restrict administrative access to the device to trusted users only.
Proactive Monitoring: Monitor device logs for unusual activity, specifically looking for unexpected process execution or suspicious shell commands originating from the log download interface.
Compensating Controls: Implement strict network segmentation to ensure the management interface of the EX3301-T0 is not exposed to untrusted segments of the network.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high impact of arbitrary command execution, users of the Zyxel EX3301-T0 should prioritize hardening their authentication mechanisms to prevent unauthorized access. Monitor vendor communications for official patch releases and apply them as soon as they become available to mitigate this high-severity risk.