Zyxel EX3510-B0
cpe:2.3:h:zyxel:ex3510-b0:*:*:*:*:*:*:*, +1 more
- <= 5.17(ABUP.15.1)C0
A command injection vulnerability has been identified in the UPnP function of the Zyxel EX3510-B0 firmware, affecting versions through 5.17(ABUP.15.1)C0. This vulnerability could allow a remote attacker to execute operating system commands on the affected device by sending specially crafted UPnP SOAP requests. The issue arises because the UPnP function can be exploited remotely if both WAN access and UPnP are enabled, despite WAN access being disabled by default.
Exploitation of this vulnerability could lead to unauthorized execution of operating system commands on the affected device.
Users can update to Zyxel's EX3510-B0 firmware version 5.17(ABUP.15.2)C0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.