CVE-2026-1459

7.2

Zyxel · VMG3625-T50B

An authenticated command injection vulnerability exists in the TR-369 certificate download CGI program of Zyxel VMG3625-T50B firmware.

Executive summary

An authenticated command injection flaw in Zyxel VMG3625-T50B firmware allows an attacker with administrator privileges to execute arbitrary OS commands, posing a high risk of total system compromise.

Vulnerability

This is an OS command injection vulnerability (CWE-78) triggered via the TR-369 certificate download CGI program. Exploitation requires the attacker to possess administrative authentication to the device.

Business impact

The vulnerability carries a CVSS score of 7.2, reflecting a high risk of total system compromise including loss of confidentiality, integrity, and availability. Successful exploitation allows an attacker to gain full control over the networking equipment, potentially leading to unauthorized network access, data exfiltration, or the deployment of persistent threats within the local environment.

Remediation

Immediate Action: Administrators should restrict management access to the device to trusted IP addresses only and monitor for official firmware updates from the Zyxel support portal to address this flaw.

Proactive Monitoring: Review system logs for unusual administrative logins or anomalous activity originating from the TR-369 service interface.

Compensating Controls: Ensure the web management interface is not exposed to the public internet and utilize network segmentation to limit the impact of a potential compromise.

Exploitation status

Public Exploit Available: Yes — a public proof-of-concept exists via a GitHub repository.

Analyst recommendation

Given the severity of potential OS command injection, administrators must treat this vulnerability with high priority. We strongly recommend limiting administrative access to the device and applying the vendor-provided firmware update as soon as it becomes available to remediate the underlying injection vulnerability.

More Zyxel CVEs