CVE-2026-6837
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
04/08/2026
Last modified:
05/08/2026
Description
A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH



