Cyber Security News

Zyxel Patches Command Injection Flaw in 18 Access Points Allowing Root OS Command Execution

Zyxel has released firmware updates for a high-severity command injection vulnerability, tracked as CVE-2026-6837, affecting 18 wireless access point models.

The flaw exists in the export-cgi component and could allow an authenticated administrator to execute operating-system commands on vulnerable devices.

The issue affects the PKCS#12 certificate export workflow. Security researcher Mina Nageh Salama reported that the certificate export password parameter could be inserted into a shell command without safe argument handling.

An attacker with a valid administrator session could abuse specially crafted input to escape the expected command context and run additional commands.

Technical analysis of Zyxel WAX650S firmware version 7.10(ABRM.4)C0 found that export-cgi built a command string containing certificate-export values before sending it to the system shell.

The unsafe design allowed shell metacharacters, including quotation marks, to alter the intended command structure. Because the CGI process executed in a highly privileged device context, successful exploitation could lead to root-level OS command execution.

Zyxel Patches Command Injection Flaw

The vulnerability is classified as CWE-78, or improper neutralization of special elements used in an operating-system command. NVD describes the issue as post-authentication, meaning it requires an attacker to first obtain administrator-level access to the access point.

Even so, the impact is significant because a compromised admin account, reused credential, exposed management interface, or malicious insider could turn the bug into complete device takeover.

According to researcher Mina Nageh Salama, reports indicate that the proof of concept was reproduced in a fully emulated WAX650S user-space environment rather than on physical hardware.

The research used extracted AArch64 firmware, qemu-aarch64-static, Bubblewrap, Python, Bash, and a recreated web-handler environment.

This allowed the analyst to reach the Lighttpd and export-cgi request path, seed required IPC services, and observe command output returned through the HTTP response.

Zyxel confirmed that 18 AP models are affected, including NWA50AX, NWA50AX PRO, NWA55AXE, NWA55AX PRO, NWA55AX PTP, NWA90AX, NWA90AX PRO, NWA110AX, NWA210AX, NWA220AX-6E, WAX300H, WAX510D, WAX610D, WAX620D-6E, WAX630S, WAX640S-6E, WAX650S, and WAX655E.

The vendor’s August 4, 2026 advisory lists firmware 7.12 builds as the fixed release line for these models. For WAX650S, administrators should update to version 7.12(ABRM.0)C0.

Organizations should promptly identify affected Zyxel APs, apply the matching firmware update, and ensure web-based management interfaces are not exposed to untrusted networks.

Administrators should also rotate privileged credentials where exposure is suspected, limit management access with network segmentation, and review device logs for suspicious certificate-export activity.

The underlying lesson is clear: appliance firmware should avoid constructing shell commands from user-controlled data. Developers should use non-shell execution interfaces with separated arguments and strict input validation, rather than rely on quoting inside a dynamically assembled command string.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

2 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

3 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

3 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

5 hours ago