Impact
The vulnerability is a command injection flaw that is executed only after a user authenticates with administrator privileges. An attacker who can log into the Zyxel WAX650S device can trigger arbitrary operating‑system commands through the vulnerable "export-cgi" program, thereby compromising the confidentiality, integrity, and availability of the affected network device. The weakness is classified as an OS Command Injection (CWE‑78) and is reflected in the CVSS score of 7.2.
Affected Systems
Zyxel WAX650S access points and security routers running firmware versions up to and including 7.10(ABRM.4)C0 are affected. Devices with later firmware revisions are not impacted.
Risk and Exploitability
The CVSS base score of 7.2 signifies high severity; however, exploitation requires pre‑existing authenticated administrator credentials. Because no EPSS value is reported and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is uncertain. Based on the requirement for administrator credentials, it is inferred that weak or poorly managed administrator accounts could further increase the risk.
OpenCVE Enrichment