Security News Zyxel Patches Command Injection Flaw in 18 Access Points Allowing Root OS Command Execution

Security News
0 Replies 332 Views

Parkinsond

Level 67
Verified
Top Poster
Well-known
Zyxel has released firmware updates for a high-severity command injection vulnerability, tracked as CVE-2026-6837, affecting 18 wireless access point models.

The flaw exists in the export-cgi component and could allow an authenticated administrator to execute operating-system commands on vulnerable devices.

The issue affects the PKCS#12 certificate export workflow. Security researcher Mina Nageh Salama reported that the certificate export password parameter could be inserted into a shell command without safe argument handling.

 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top