Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4989 articles · 189008 vulns · 37/41 feeds (7d)
← Back to list
7.2
CVE-2026-6837PATCHED
zyxel · wax650s firmware

CVE-2026-6837: A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions

Description

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

Affected Products

VendorProductVersions
zyxelwax650s firmware<= 7.10(ABRM.4)C0

References

  • https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026(vendor-advisory)

Related News (1 articles)

Tier C
VulDB8d ago
CVE-2026-6837 | Zyxel WAX650S up to 7.10(ABRM.4)C0 export-cgi export.cgi os command injection
→ No new info (linked only)
CVSS 3.17.2 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026
CWECWE-78
PublishedAug 4, 2026
Trending Score10
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-13206
Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection
Trending: 33
HIGHCVE-2026-12984
Exposure of Sensitive Information to an Unauthorized Actor in Zyxel's WAH7601
Trending: 27
HIGHCVE-2026-6374
Hardcoded Credentials in Zyxel WAH7601 Router
Trending: 23
MEDIUMCVE-2026-6373
Sensitive Data Exposure in Zyxel WAH7601 Router
Trending: 15
HIGHCVE-2026-14818
CVE-2026-14818: A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versi
Trending: 15

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 4, 2026
Discovered by ZDM
Aug 4, 2026
Patch Available
Aug 5, 2026