PT-2026-21645 · Zyxel · Zyxel Vmg3625-T50B

CVE-2026-1459

·

Published

2026-02-24

·

Updated

2026-03-01

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0
Description A post-authentication command injection exists in the TR-369 certificate download CGI program. An authenticated attacker with administrator privileges could execute operating system (OS) commands on an affected device. The vulnerable component is the TR-369 certificate download CGI program.
Recommendations Versions prior to 5.50(ABPM.9.7)C0 should be updated.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1459

Affected Products

Zyxel Vmg3625-T50B