{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-13206/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-13206"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WAH7601"],"_cs_severities":["critical"],"_cs_tags":["cve-2026-13206","command-injection","zyxel","network-device","rce","credential-access","vulnerability","networking","network-security"],"_cs_type":"advisory","_cs_vendors":["Zyxel"],"content_html":"\u003cp\u003eZyxel WAH7601 mobile Wi-Fi devices are vulnerable to an OS command injection flaw tracked as CVE-2026-13206. This vulnerability arises from the improper neutralization of special elements within OS commands, allowing an attacker to inject and execute arbitrary commands on the underlying device operating system. The flaw affects all firmware versions up to and including 20072026. Given the critical CVSS base score of 9.8, this vulnerability poses a severe risk to network infrastructure security. Defenders should treat this as a high-priority patch item, as successful exploitation results in full device compromise, potentially facilitating lateral movement into connected networks or interception of wireless traffic.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-13206 allows unauthenticated attackers to achieve remote code execution (RCE) on the Zyxel WAH7601. This can lead to total device takeover, persistence through firmware manipulation, exfiltration of administrative credentials, and the redirection of wireless traffic for man-in-the-middle attacks within the local environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all Zyxel WAH7601 devices on the internal network that are reachable via management interfaces.\u003c/li\u003e\n\u003cli\u003eApply the latest firmware updates provided by Zyxel to address CVE-2026-13206.\u003c/li\u003e\n\u003cli\u003eRestrict management interface access to trusted administrative source IPs using local firewall or VLAN segmentation rules.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual web management traffic or unexpected system command execution originating from the device.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-10T13:32:12Z","date_published":"2026-08-10T13:31:05Z","id":"https://feed.craftedsignal.io/briefs/2026-08-zyxel-command-injection/","summary":"An OS command injection vulnerability in Zyxel WAH7601 devices (CVE-2026-13206) allows unauthenticated remote attackers to execute arbitrary system commands.","title":"OS Command Injection Vulnerability in Zyxel WAH7601","url":"https://feed.craftedsignal.io/briefs/2026-08-zyxel-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-13206","version":"https://jsonfeed.org/version/1.1"}