Executive brief
A security vulnerability exists in several Zyxel networking devices, including certain 4G LTE, 5G, and DSL routers. An attacker on the same local network could exploit this flaw to crash the device's Universal Plug and Play (UPnP) service, which is used for automatic port discovery and configuration. While the device will continue to route general internet traffic, the UPnP feature will become unavailable until the service is restored.
Technical details
This vulnerability is a classic buffer overflow (CWE-120) located within the UPnP DeletePortMapping() command handler. An unauthenticated attacker located on the same local area network (LAN/WLAN) can send a specially crafted UPnP request to trigger the overflow. Successful exploitation results in a temporary denial-of-service (DoS) specifically affecting the UPnP daemon. The device's primary packet forwarding and network traffic processing capabilities remain functional during the attack. Patches have been released for affected models, including firmware versions 5.13(ABRL.5.5)C0 for the VMG4005-B50B and 1.00(ABUV.12)B4 for the NR7101.
Affected products
- Zyxel NR7101 1.00(ABUV.11)C0 and earlier
- Zyxel Nebula LTE3301-PLUS 1.18(ACCA.6)C0 and earlier
- Zyxel Nebula NR7101 1.16(ACCC.1)C0 and earlier
- Zyxel VMG4005-B50B 5.13(ABRL.5.4)C0 and earlier
Timeline
- 2026-06-01: disclosed: Initial disclosure by Zyxel Corporation
- 2026-06-02: advisory: NVD publication date