Zyxel Patches Command Injection Flaw in 18 Access Points Allowing Root OS Command Execution
ID: 681653c2-09cc-55fb-9760-4c37eb393695
STIX ID: report--681653c2-09cc-55fb-9760-4c37eb393695
Feed Name: cybersecurityNews.com
**Executive summary:** Zyxel disclosed a high-severity post-authentication command injection (CVE-2026-6837) in the export-cgi certificate export process of 18 access point models that allows an authenticated administrator to inject shell metacharacters and achieve root-level command execution; a researcher reproduced a PoC in an emulated WAX650S firmware environment and Zyxel issued firmware 7.12 builds as fixes and recommends immediate patching, credential rotation, and limiting web management exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
