Skip to content
Threat Feed

Tag

Zyxel

4 briefs RSS
critical advisory

OS Command Injection Vulnerability in Zyxel WAH7601

An OS command injection vulnerability in Zyxel WAH7601 devices (CVE-2026-13206) allows unauthenticated remote attackers to execute arbitrary system commands.

WAH7601 cve-2026-13206 command-injection zyxel network-device rce credential-access vulnerability networking +1
3t 1c
high advisory

Command Injection in Zyxel WAX650S export-cgi

An authenticated administrator can exploit a command injection vulnerability in the export-cgi program of Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 to execute arbitrary OS commands.

PoC WAX650S firmware +1 cve command-injection zyxel network-infrastructure
1r 1t 1c updated
high advisory

Zyxel WRE6505 v2 Command Injection Vulnerability (CVE-2026-7256)

A command injection vulnerability (CVE-2026-7256) in Zyxel WRE6505 v2 firmware allows an adjacent attacker on the LAN to execute arbitrary OS commands by sending a crafted HTTP request.

WRE6505 v2 firmware version V1.00 command injection zyxel cve-2026-7256 network device
2r 1t 1c
critical advisory

Critical Command Injection Vulnerability in Zyxel Routers (CVE-2026-13942)

A critical command injection vulnerability (CVE-2026-13942) in the UPnP function of Zyxel routers allows remote attackers to execute arbitrary operating system commands by sending crafted UPnP SOAP requests.

zyxel router command injection cve-2026-13942 upnp
2r 1t