PT-2026-67633 · Zyxel · Wax650S

CVE-2026-6837

·

Published

2026-08-03

·

Updated

2026-08-21

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zyxel WAX650S versions prior to 7.10(ABRM.4)C0
Description A post-authentication command injection issue exists in the "export-cgi" CGI program. This allows an authenticated attacker with administrator privileges to execute arbitrary operating system commands on the device.
Recommendations Update to a version newer than 7.10(ABRM.4)C0.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11899
CVE-2026-6837

Affected Products

Wax650S