Junglewise Threat Intelligence

CVE-2026-3871: Zyxel multiple CPE devices buffer overflow in UPnP DeletePortMapping

CVE-2026-3871 · Severity: medium · CVSS 6.5 · Published 2026-06-02

Vendors: Zyxel.

Executive brief

A security vulnerability exists in several Zyxel networking devices, including certain 4G LTE, 5G, and DSL routers. An attacker on the same local network could exploit this flaw to crash the device's Universal Plug and Play (UPnP) service, which is used for automatic port discovery and configuration. While the device will continue to route general internet traffic, the UPnP feature will become unavailable until the service is restored.

Technical details

This vulnerability is a classic buffer overflow (CWE-120) located within the UPnP DeletePortMapping() command handler. An unauthenticated attacker located on the same local area network (LAN/WLAN) can send a specially crafted UPnP request to trigger the overflow. Successful exploitation results in a temporary denial-of-service (DoS) specifically affecting the UPnP daemon. The device's primary packet forwarding and network traffic processing capabilities remain functional during the attack. Patches have been released for affected models, including firmware versions 5.13(ABRL.5.5)C0 for the VMG4005-B50B and 1.00(ABUV.12)B4 for the NR7101.

Affected products

  • Zyxel NR7101 1.00(ABUV.11)C0 and earlier
  • Zyxel Nebula LTE3301-PLUS 1.18(ACCA.6)C0 and earlier
  • Zyxel Nebula NR7101 1.16(ACCC.1)C0 and earlier
  • Zyxel VMG4005-B50B 5.13(ABRL.5.4)C0 and earlier

Timeline

  • 2026-06-01: disclosed: Initial disclosure by Zyxel Corporation
  • 2026-06-02: advisory: NVD publication date

References

Related threats