ZeroHour

CVE-2026-1460

CVSS 3.1
7.2 high
EPSS
1%p65
Published
()
Modified
Description

A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

Vendors
zyxel
Products
nebula fwa70 firmware, nebula fwa505 firmware, nebula fwa510 firmware, nebula fwa515 firmware, nebula fwa710 firmware, nebula lte3301-plus firmware, nebula lte7461-m602 firmware, nebula nr5101 firmware, nebula nr7101 firmware, dx3300-t0 firmware, dx3300-t1 firmware, dx3301-t0 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.