Description
A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 28 Apr 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zyxel
Zyxel dx3301-t0 Firmware Zyxel ex3301-t0 Firmware |
|
| Vendors & Products |
Zyxel
Zyxel dx3301-t0 Firmware Zyxel ex3301-t0 Firmware |
Tue, 28 Apr 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zyxel
Published:
Updated: 2026-04-28T02:06:22.568Z
Reserved: 2026-01-27T01:26:25.772Z
Link: CVE-2026-1460
No data.
Status : Received
Published: 2026-04-28T03:16:02.313
Modified: 2026-04-28T03:16:02.313
Link: CVE-2026-1460
No data.
OpenCVE Enrichment
Updated: 2026-04-28T04:45:22Z
Weaknesses