← Back

CVE-2026-1459

nvd nist
Published: Feb 24, 2026Modified: Jun 17, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on an affected device.

Affected (6)

6 products
Vmg3625 T50c Firmware
Vmg3625 T50b Firmware
Emg5523 T50b Firmware
Emg3525 T50b Firmware
Dx5401 B1 Firmware
Vmg8623 T50b Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.50\(abpm.9.7\)c0
Running on/withPlatform Versions
Zyxel
Vmg3625 T50c
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.50\(abpm.9.7\)c0
Running on/withPlatform Versions
Zyxel
Vmg3625 T50b
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.50\(abpm.9.7\)c0
Running on/withPlatform Versions
Zyxel
Emg5523 T50b
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.50\(abpm.9.7\)c0
Running on/withPlatform Versions
Zyxel
Emg3525 T50b
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.17\(abyo.7.1\)c0
Running on/withPlatform Versions
Zyxel
Dx5401 B1
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.50\(abpm.9.7\)c0
Running on/withPlatform Versions
Zyxel
Vmg8623 T50b
All versions

Timeline

No history available yet.