CVE-2026-1459
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
24/02/2026
Last modified:
25/02/2026
Description
A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on an affected device.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:zyxel:vmg8623-t50b_firmware:*:*:*:*:*:*:*:* | 5.50\(abpm.9.7\)c0 (including) | |
| cpe:2.3:h:zyxel:vmg8623-t50b:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:dx5401-b1_firmware:*:*:*:*:*:*:*:* | 5.17\(abyo.7.1\)c0 (including) | |
| cpe:2.3:h:zyxel:dx5401-b1:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:emg3525-t50b_firmware:*:*:*:*:*:*:*:* | 5.50\(abpm.9.7\)c0 (including) | |
| cpe:2.3:h:zyxel:emg3525-t50b:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:emg5523-t50b_firmware:*:*:*:*:*:*:*:* | 5.50\(abpm.9.7\)c0 (including) | |
| cpe:2.3:h:zyxel:emg5523-t50b:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:vmg3625-t50b_firmware:*:*:*:*:*:*:*:* | 5.50\(abpm.9.7\)c0 (including) | |
| cpe:2.3:h:zyxel:vmg3625-t50b:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:vmg3625-t50c_firmware:*:*:*:*:*:*:*:* | 5.50\(abpm.9.7\)c0 (including) | |
| cpe:2.3:h:zyxel:vmg3625-t50c:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



