Zum Inhalt springen
CodeAuditAgent

CVE-2026-1460

A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

Schwachstellenklasse

A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

Betroffene Produkte

  • zyxel nebula_fwa70_firmware
  • zyxel nebula_fwa70
  • zyxel nebula_fwa505_firmware
  • zyxel nebula_fwa505
  • zyxel nebula_fwa510_firmware
  • zyxel nebula_fwa510
  • zyxel nebula_fwa515_firmware
  • zyxel nebula_fwa515

Quellen

Finden Sie die Schwachstelle, bevor es ein Angreifer tut.

Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.