Vendor
Remote Code Execution Vulnerability in Zyxel Firewalls
1 TTPA vulnerability in Zyxel firewall firmware allows a remote, authenticated attacker to achieve arbitrary code execution on the device.
Path Traversal Vulnerability in Zyxel Network Appliance CLI
1 TTP 1 CVEAn authenticated path traversal vulnerability in Zyxel ATP and USG series firmware allows administrators to execute arbitrary configuration files, potentially leading to command execution.
Command Injection in Zyxel WAX650S export-cgi
1 rule 1 TTP 1 CVEAn authenticated administrator can exploit a command injection vulnerability in the export-cgi program of Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 to execute arbitrary OS commands.
Zyxel AX7501-B1 Firmware Command Injection (CVE-2026-6952)
1 TTP 1 CVEA post-authentication command injection vulnerability (CVE-2026-6952) in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 allows an authenticated attacker with administrator privileges to execute arbitrary OS commands on the affected device.
CVE-2026-7287 - Zyxel NWA1100-N Buffer Overflow Vulnerability
2 rules 2 TTPs 1 CVEA buffer overflow vulnerability in Zyxel NWA1100-N firmware allows a remote attacker to cause a denial-of-service by sending a crafted HTTP request to the webs binary.
Zyxel WRE6505 v2 Command Injection Vulnerability (CVE-2026-7256)
2 rules 1 TTP 1 CVEA command injection vulnerability (CVE-2026-7256) in Zyxel WRE6505 v2 firmware allows an adjacent attacker on the LAN to execute arbitrary OS commands by sending a crafted HTTP request.
Zyxel Command Injection Vulnerabilities in CPE and Extenders
2 rules 1 TTPZyxel released a security advisory on April 28, 2026, addressing command injection vulnerabilities across multiple versions of their 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, and Wireless Extender products, potentially allowing attackers to execute arbitrary commands.