Skip to content
CodeAuditAgent

CVE-2026-0711

A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS commands on an affected device.

Weakness

A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS commands on an affected device.

Affected products

  • zyxel nr5307_firmware
  • zyxel nr5307
  • zyxel nebula_fwa515_firmware
  • zyxel nebula_fwa515
  • zyxel dx3300-t0_firmware
  • zyxel dx3300-t0
  • zyxel dx3300-t1_firmware
  • zyxel dx3300-t1

References

Find the bug before an attacker does.

Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.