Impact
Zyxel Networks WAH7601 routers are vulnerable to OS command injection due to improper sanitization of special elements provided to an operating system shell. When an attacker is able to supply a crafted input to the affected parameter, arbitrary shell commands can be executed with the privilege level of the device. This flaw can lead to complete compromise, allowing attackers to read configuration, reset the device, or use the router as a pivot point for further attacks. The weakness is identified as CWE‑78.
Affected Systems
Affected systems include Zyxel Networks WAH7601 devices, specifically versions up to and including 20072026. No earlier versions are listed as impacted, and the CVE states that the vulnerability exists through the indicated release series.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical level of risk. EPSS is not available, so no quantified probability of exploitation is provided, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, inferred from the nature of the command injection and typical management interfaces on routers. Exploitation would generally require network-level access to the device's management interface, though public exposure of that interface could further increase risk.
OpenCVE Enrichment