<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Zyxel — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/zyxel/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 27 Feb 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/zyxel/feed.xml" rel="self" type="application/rss+xml"/><item><title>Critical Command Injection Vulnerability in Zyxel Routers (CVE-2026-13942)</title><link>https://feed.craftedsignal.io/briefs/2026-02-zyxel-rce/</link><pubDate>Fri, 27 Feb 2026 12:00:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-02-zyxel-rce/</guid><description>A critical command injection vulnerability (CVE-2026-13942) in the UPnP function of Zyxel routers allows remote attackers to execute arbitrary operating system commands by sending crafted UPnP SOAP requests.</description><content:encoded>&lt;p>A critical command injection vulnerability, tracked as CVE-2026-13942, has been discovered in the UPnP (Universal Plug and Play) service of Zyxel routers. The vulnerability stems from insufficient validation of input within the UPnP SOAP request processing.  An unauthenticated, remote attacker can exploit this flaw by sending specially crafted UPnP SOAP requests to the affected device. This allows the attacker to inject and execute arbitrary operating system commands with elevated privileges on…&lt;/p>
</content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>zyxel</category><category>router</category><category>command injection</category><category>cve-2026-13942</category><category>upnp</category></item></channel></rss>