Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4505 articles · 223844 vulns · 37/41 feeds (7d)
← Back to list
EST
PRE-CVE
zyxel

Post-authentication command injection in Zyxel DSL/Ethernet CPE, Fiber ONTs, and Wireless Extenders

72% confidence

Description

A post-authentication command injection vulnerability exists in certain Zyxel DSL/Ethernet CPE, Fiber ONTs, and Wireless Extenders that could allow an authenticated attacker to execute arbitrary commands.

Affected Products

VendorProductVersions
zyxel——

Related News (1 articles)

Tier B
CCCS Canada68d ago
Zyxel security advisory (AV26-725)
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV❌ No
Actively exploited❌ No
CWECWE-78
PublishedJul 21, 2026
Last enriched68d ago
Tags
command injectionpost-authenticationcpeontwireless extender
Trending Score0
Source articles1
Independent1
Info Completeness5/14
Missing: cve_id, product, versions, cvss, epss, kev, exploit, patch, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-8508
CVE-2026-8508: An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug
Trending: 2
HIGHCVE-2026-6837
CVE-2026-6837: A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions
Trending: 1
HIGHCVE-2026-14818
CVE-2026-14818: A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versi
CRITICALCVE-2026-13206
Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection
HIGHCVE-2026-6374
Hardcoded Credentials in Zyxel WAH7601 Router

Pin to Dashboard

Verification

State: reported
Confidence: 72%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026