Description
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection.

This issue affects WAH7601: through 20072026.
Published: 2026-08-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Zyxel Networks WAH7601 routers are vulnerable to OS command injection due to improper sanitization of special elements provided to an operating system shell. When an attacker is able to supply a crafted input to the affected parameter, arbitrary shell commands can be executed with the privilege level of the device. This flaw can lead to complete compromise, allowing attackers to read configuration, reset the device, or use the router as a pivot point for further attacks. The weakness is identified as CWE‑78.

Affected Systems

Affected systems include Zyxel Networks WAH7601 devices, specifically versions up to and including 20072026. No earlier versions are listed as impacted, and the CVE states that the vulnerability exists through the indicated release series.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical level of risk. EPSS is not available, so no quantified probability of exploitation is provided, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, inferred from the nature of the command injection and typical management interfaces on routers. Exploitation would generally require network-level access to the device's management interface, though public exposure of that interface could further increase risk.

Generated by OpenCVE AI on August 10, 2026 at 13:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Zyxel’s official website or support portal for a firmware update that addresses the OS command injection flaw.
  • Restrict access to the router’s management interface to trusted internal networks and block inbound access from the internet if possible.
  • If a patch is not immediately available, disable remote or web-based management features, or place the device behind a firewall block permitting only authorized IP ranges.

Generated by OpenCVE AI on August 10, 2026 at 13:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection. This issue affects WAH7601: through 20072026.
Title Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-10T18:00:46.712Z

Reserved: 2026-06-24T14:19:59.058Z

Link: CVE-2026-13206

cve-icon Vulnrichment

Updated: 2026-08-10T18:00:42.481Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T13:30:05Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')