CVE-2026-13206

9.8

Zyxel Networks · WAH7601

An OS command injection vulnerability in Zyxel WAH7601 allows unauthenticated remote attackers to execute arbitrary commands on the affected device.

Executive summary

A critical OS command injection vulnerability in Zyxel WAH7601 devices permits unauthenticated remote code execution, posing a severe risk to device integrity.

Vulnerability

This is an OS command injection flaw (CWE-78) triggered by the improper neutralization of special characters in input fields. The vulnerability is accessible to unauthenticated remote attackers, requiring no specific user privileges to trigger.

Business impact

Successful exploitation allows an attacker to gain full control over the affected hardware, potentially leading to total system compromise, network surveillance, or use of the device in botnet activities. Given the CVSS score of 9.8, this vulnerability represents a critical threat to infrastructure security and data confidentiality.

Remediation

Immediate Action: Update the Zyxel WAH7601 firmware to the latest available version provided by the vendor.

Proactive Monitoring: Monitor network traffic for unusual outbound connections from the management interface and inspect device logs for signs of unauthorized command execution.

Compensating Controls: Restrict access to the device management interface to trusted internal IP addresses using firewall rules to prevent external exposure.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

Due to the critical severity and the potential for complete remote device takeover, administrators must prioritize the application of firmware updates. If an update cannot be applied immediately, the device should be isolated from the public internet to mitigate the risk of exploitation.

More Zyxel Networks CVEs