← Back to CVE List
CVE-2026-1459NVD
Vulnerability Summary
A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on an affected device.
CVSS v3.1 Base Metrics — Score 7.2 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Zyxel Vmg8623-t50b Firmware <= 5.50\(abpm.9.7\)c0
- Zyxel Dx5401-b1 Firmware <= 5.17\(abyo.7.1\)c0
- Zyxel Emg3525-t50b Firmware <= 5.50\(abpm.9.7\)c0
- Zyxel Emg5523-t50b Firmware <= 5.50\(abpm.9.7\)c0
- Zyxel Vmg3625-t50b Firmware <= 5.50\(abpm.9.7\)c0
- Zyxel Vmg3625-t50c Firmware <= 5.50\(abpm.9.7\)c0
Not provided by NVD for this CVE.