OS Command Injection in ZyXEL Communications Corp. products - CVE-2026-6837

 

OS Command Injection in ZyXEL Communications Corp. products - CVE-2026-6837

Published: August 4, 2026


Vulnerability identifier: #VU140856
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-6837
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation in the "export-cgi" CGI program. A remote administrator can pass specially crafted data to the application and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

NWA50AX
WAX300H
NWA220AX-6E
WAX620D-6E
NWA90AX PRO
WAX630S
NWA90AX
WAX640S-6E
NWA55AX PTP
NWA55AX PRO
NWA55AXE
WAX655E
NWA50AX PRO
WAX510D
WAX610D
NWA210AX
NWA110AX
WAX650S

How to mitigate CVE-2026-6837

Install updates from vendor's website.

NWA50AX - update to 7.12(ABYW.0)C0
WAX510D - update to 7.12(ABTF.0)C0
WAX610D - update to 7.12(ABTE.0)C0
WAX300H - update to 7.12(ACHF.0)C0
NWA220AX-6E - update to 7.12(ACCO.0)C0
NWA210AX - update to 7.12(ABTD.0)C0
NWA110AX - update to 7.12(ABTG.0)C0
WAX620D-6E - update to 7.12(ACCN.0)C0
NWA90AX PRO - update to 7.12(ACGF.0)C0
WAX630S - update to 7.12(ABZD.0)C0
NWA90AX - update to 7.12(ACCV.0)C0
WAX640S-6E - update to 7.12(ACCM.0)C0
NWA55AX PTP - update to 7.12(ACSQ.0)C0
WAX650S - update to 7.12(ABRM.0)C0
NWA55AX PRO - update to 7.12(ACSP.0)C0
NWA55AXE - update to 7.12(ABZL.0)C0
WAX655E - update to 7.12(ACDO.0)C0
NWA50AX PRO - update to 7.12(ACGE.0)C0

External References

Related Security Bulletins