logo

Zyxel Patches Command Injection Flaw in 18 Access Points Allowing Root OS Command Execution

ID: 681653c2-09cc-55fb-9760-4c37eb393695

STIX ID: report--681653c2-09cc-55fb-9760-4c37eb393695

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-08-20

Date Updated: 2026-08-21

Author: Abinaya

...
...

**Executive summary:** Zyxel disclosed a high-severity post-authentication command injection (CVE-2026-6837) in the export-cgi certificate export process of 18 access point models that allows an authenticated administrator to inject shell metacharacters and achieve root-level command execution; a researcher reproduced a PoC in an emulated WAX650S firmware environment and Zyxel issued firmware 7.12 builds as fixes and recommends immediate patching, credential rotation, and limiting web management exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.