Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 04 Aug 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zyxel
Zyxel wax650s Firmware |
|
| Vendors & Products |
Zyxel
Zyxel wax650s Firmware |
Tue, 04 Aug 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zyxel
Published:
Updated: 2026-08-04T01:52:07.780Z
Reserved: 2026-04-22T03:09:29.255Z
Link: CVE-2026-6837
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-04T03:30:03Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')