HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-6837 — A post-authentication command injection vulnerability in the "export-cgi" CGI pr...
·Source: NIST NVD
Updated:
Executive Summary
A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
Analysis
A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device. CVSS Score: 7.2. Published: 2026-08-04T03:16:25.890.