CVE-2026-6837: OS Command Injection
Published Aug 4, 2026
·Updated
A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
Affected Software
1 affected component
Zyxel Wax650s Firmware<=7.10(ABRM.4)C0
Event History
Aug 4, 2026
CVE Published
via MITRE·01:52 AM
Data Sourced
via MITRE·01:52 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-6837?
CVE-2026-6837 has a severity rating of 7.2, indicating a high risk.
2
How do I fix CVE-2026-6837?
To mitigate CVE-2026-6837, upgrade your Zyxel WAX650S firmware to the latest version beyond 7.10(ABRM.4)C0.
3
What impact does CVE-2026-6837 have on my device?
CVE-2026-6837 allows authenticated attackers with administrator privileges to execute OS commands, potentially compromising your device.
4
Is CVE-2026-6837 a post-authentication vulnerability?
Yes, CVE-2026-6837 is a post-authentication command injection vulnerability.
5
Which firmware versions are affected by CVE-2026-6837?
CVE-2026-6837 affects Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0.