CVE-2026-0711
A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS commands on an affected device.
Weakness
A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS commands on an affected device.
Affected products
- zyxel nr5307_firmware
- zyxel nr5307
- zyxel nebula_fwa515_firmware
- zyxel nebula_fwa515
- zyxel dx3300-t0_firmware
- zyxel dx3300-t0
- zyxel dx3300-t1_firmware
- zyxel dx3300-t1
References
Find the bug before an attacker does.
Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.