Security News Zyxel Patches Command Injection Flaw in 18 Access Points Allowing Root OS Command Execution

Parkinsond

Level 65
Thread author
Verified
Top Poster
Well-known
Dec 6, 2023
5,451
17,407
6,369
Zyxel has released firmware updates for a high-severity command injection vulnerability, tracked as CVE-2026-6837, affecting 18 wireless access point models.

The flaw exists in the export-cgi component and could allow an authenticated administrator to execute operating-system commands on vulnerable devices.

The issue affects the PKCS#12 certificate export workflow. Security researcher Mina Nageh Salama reported that the certificate export password parameter could be inserted into a shell command without safe argument handling.

 
  • Like
Reactions: Khushal