SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-6837

HIGH · CVSS 7.2 EPSS 1.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-09-03

CyberRota Analysis

AI-Generated

A post-authentication command injection vulnerability exists in the "export-cgi" CGI program of Zyxel WAX650S firmware versions up to 7.10(ABRM.4)C0, allowing authenticated attackers with administrator privileges to execute arbitrary OS commands on the device. This high-severity flaw poses a significant risk to network security, as it can lead to unauthorized access and control over affected devices. Organizations using the specified firmware should prioritize patching this vulnerability to mitigate potential exploitation.

CVE
CVE-2026-6837
Severity
HIGH
CVSS
7.2
EPSS
1.17%

Original NVD Description

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.