CVE-2026-6837
A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
- Affected products
- Wax650S
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 0.9% (58th percentile)
- Weakness
- CWE-78
- NVD status
- Awaiting Analysis
- Published
- 2026-08-04
CVE-2026-6837 at NVD
1 known exploit for CVE-2026-6837
Proof-of-concept code and exploit modules indexed by Sploitus