CVE-2026-0711
Analyzed Analyzed - Analysis Complete

Post-Auth Command Injection in Zyxel DX3300-T0 EasyMesh APIs

Vulnerability report for CVE-2026-0711, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-04-28

Last updated on: 2026-07-25

Assigner: Zyxel Corporation

Description

A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS commands on an affected device.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-04-28
Last Modified
2026-07-25
Generated
2026-07-27
AI Q&A
2026-04-28
EPSS Evaluated
2026-07-25
NVD
EUVD

Affected Vendors & Products

Showing 36 associated CPEs
Vendor Product Version / Range
zyxel nr5307_firmware to 2.00(acjt.3 (exc)
zyxel nebula_fwa515_firmware to 1.60(acpz.0 (exc)
zyxel dx3300-t0_firmware to 5.50(abvy.7.2 (exc)
zyxel dx3300-t1_firmware to 5.50(abvy.7.2 (exc)
zyxel dx3301-t0_firmware to 5.50(abvy.7.2 (exc)
zyxel dx5401-b0_firmware to 5.17(abyo.7.2 (exc)
zyxel dx5401-b1_firmware to 5.17(abyo.7.2 (exc)
zyxel ee3301-00_firmware to 5.63(acmu.3.1 (exc)
zyxel ee5301-00_firmware to 5.63(acld.3.1 (exc)
zyxel ee6510-10_firmware to 5.19(acjq.4.2 (exc)
zyxel emg3525-t50b_firmware to 5.50(abpm.9.8 (exc)
zyxel emg5523-t50b_firmware to 5.50(abpm.9.8 (exc)
zyxel ex3300-t0_firmware to 5.50(abvy.7.2 (exc)
zyxel ex3300-t1_firmware to 5.50(abvy.7.2 (exc)
zyxel ex3301-t0_firmware to 5.50(abvy.7.2 (exc)
zyxel ex3500-t0_firmware to 5.44(achr.6 (exc)
zyxel ex3501-t0_firmware to 5.44(achr.6 (exc)
zyxel ex3600-t0_firmware to 5.70(acif.3 (exc)
zyxel ex5401-b0_firmware to 5.17(abyo.7.2 (exc)
zyxel ex5401-b1_firmware to 5.17(abyo.7.2 (exc)
zyxel ex5512-t0_firmware to 5.70(aceg.5.5 (exc)
zyxel ex5601-t0_firmware to 5.70(acdz.6 (exc)
zyxel ex5601-t1_firmware to 5.70(acdz.6 (exc)
zyxel ex7501-b0_firmware to 5.18(achn.3.2 (exc)
zyxel vmg3625-t50b_firmware to 5.50(abpm.9.8 (exc)
zyxel vmg8623-t50b_firmware to 5.50(abpm.9.8 (exc)
zyxel ax7501-b0_firmware to 5.17(abpc.7.2 (exc)
zyxel ax7501-b1_firmware to 5.17(abpc.7.2 (exc)
zyxel pe3301-00_firmware to 5.63(acmt.3.1 (exc)
zyxel pe5301-01_firmware to 5.63(acoj.3.1 (exc)
zyxel px5302-00_firmware to 5.44(acnm.0.1 (exc)
zyxel px5301-t0_firmware to 5.44(ackb.0.7 (exc)
zyxel we3300-00_firmware to 5.70(acka.2 (exc)
zyxel wx3100-t0_firmware to 5.50(abvl.4.10 (exc)
zyxel we4600-00_firmware to 6.70(ackt.1 (exc)
zyxel wx5600-t0_firmware to 5.70(aceb.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a post-authentication command injection issue found in the EasyMesh-related APIs of Zyxel DX3300-T0 devices running firmware versions up to 5.50(ABVY.7.1)C0.

An attacker who is authenticated and adjacent to the device, and who has administrator privileges, could exploit this vulnerability to execute arbitrary operating system commands on the affected device.

Impact Analysis

Exploitation of this vulnerability could allow an attacker with administrator access to execute arbitrary OS commands on the device, potentially leading to full control over the device.

  • Compromise of device integrity and availability.
  • Potential unauthorized access to sensitive data or network resources.
  • Disruption of network services relying on the affected device.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-0711. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart