Zyxel has patched a critical-severity OS command execution vulnerability that is remotely exploitable via crafted UPnP requests.