CVE-2026-1460
Analyzed Analyzed - Analysis Complete

Post-Auth Command Injection in Zyxel DHCP DomainName Parameter

Vulnerability report for CVE-2026-1460, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-04-28

Last updated on: 2026-07-25

Assigner: Zyxel Corporation

Description

A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-04-28
Last Modified
2026-07-25
Generated
2026-07-26
AI Q&A
2026-04-28
EPSS Evaluated
2026-07-25
NVD
EUVD

Affected Vendors & Products

Showing 45 associated CPEs
Vendor Product Version / Range
zyxel nebula_fwa70_firmware to 1.51(acrf.0 (exc)
zyxel nebula_fwa505_firmware to 1.60(acko.3 (exc)
zyxel nebula_fwa510_firmware to 1.60(acgd.1 (exc)
zyxel nebula_fwa515_firmware to 1.60(acpz.1 (exc)
zyxel nebula_fwa710_firmware to 1.60(acgc.2 (exc)
zyxel nebula_lte3301-plus_firmware to 1.18(acca.7 (exc)
zyxel nebula_lte7461-m602_firmware to 1.15(acev.4 (exc)
zyxel nebula_nr5101_firmware to 1.16(accg.1 (exc)
zyxel nebula_nr7101_firmware to 1.16(accc.2 (exc)
zyxel dx3300-t0_firmware to 5.50(abvy.7.2 (exc)
zyxel dx3300-t1_firmware to 5.50(abvy.7.2 (exc)
zyxel dx3301-t0_firmware to 5.50(abvy.7.2 (exc)
zyxel dx5401-b1_firmware to 5.17(abyo.7.2 (exc)
zyxel ee3301-00_firmware to 5.63(acmu.3.1 (exc)
zyxel ee5301-00_firmware to 5.63(acld.3.1 (exc)
zyxel ee6510-10_firmware to 5.19(acjq.4.2 (exc)
zyxel emg3525-t50b_firmware to 5.50(abpm.9.8 (exc)
zyxel emg5523-t50b_firmware to 5.50(abpm.9.8 (exc)
zyxel ex2210-t0_firmware to 5.50(acdi.2.5 (exc)
zyxel ex3300-t0_firmware to 5.50(abvy.7.2 (exc)
zyxel ex3300-t1_firmware to 5.50(abvy.7.2 (exc)
zyxel ex3301-t0_firmware to 5.50(abvy.7.2 (exc)
zyxel ex3500-t0_firmware to 5.44(achr.6 (exc)
zyxel ex3501-t0_firmware to 5.44(achr.6 (exc)
zyxel ex3600-t0_firmware to 5.70(acif.3 (exc)
zyxel ex5401-b1_firmware to 5.17(abyo.7.2 (exc)
zyxel ex5512-t0_firmware to 5.70(aceg.5.5 (exc)
zyxel ex5601-t0_firmware to 5.70(acdz.6 (exc)
zyxel ex5601-t1_firmware to 5.70(acdz.6 (exc)
zyxel ex7501-b0_firmware to 5.18(achn.3.2 (exc)
zyxel ex7710-b0_firmware to 5.18(acak.1.7 (exc)
zyxel gm4100-b0_firmware to 5.18(accl.2.1 (exc)
zyxel vmg3625-t50b_firmware to 5.50(abpm.9.8 (exc)
zyxel vmg4005-b50a_firmware to 5.17(abqa.3.3 (exc)
zyxel vmg4005-b60a_firmware to 5.17(abqa.3.3 (exc)
zyxel vmg8623-t50b_firmware to 5.50(abpm.9.8 (exc)
zyxel am7510-00_firmware to 5.63(acor.0.2 (exc)
zyxel ax7501-b1_firmware to 5.17(abpc.7.2 (exc)
zyxel pe3301-00_firmware to 5.63(acmt.3.1 (exc)
zyxel pe5301-01_firmware to 5.63(acoj.3.1 (exc)
zyxel px5301-t0_firmware to 5.44(ackb.0.7 (exc)
zyxel px5302-00_firmware to 5.44(acnm.0.1 (exc)
zyxel we3300-00_firmware to 5.70(acka.2 (exc)
zyxel we4600-00_firmware to 6.70(ackt.1 (exc)
zyxel wx5600-t0_firmware to 5.70(aceb.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-1460 is a post-authentication command injection vulnerability found in the "DomainName" parameter of the DHCP configuration file on certain Zyxel devices, specifically the DX3301-T0 and EX3301-T0 models with firmware versions up to 5.50(ABVY.7.1)C0.

An attacker who is already authenticated with administrator privileges on the device can exploit this vulnerability to execute arbitrary operating system commands. This means the attacker can run commands on the device's underlying OS, potentially taking full control of the device.

WAN access is disabled by default on these devices, so exploitation requires that the attacker has administrative access, typically through compromised credentials.

Detection Guidance

This vulnerability involves a post-authentication command injection in the "DomainName" parameter of the DHCP configuration file on affected Zyxel devices. Detection would require verifying if the device firmware version is vulnerable and checking for unauthorized changes or command executions related to this parameter.

Since exploitation requires administrator privileges and access to the device, detection commands could include inspecting the DHCP configuration file for suspicious entries or unexpected commands in the "DomainName" parameter.

However, no specific detection commands or network scanning methods are provided in the available resources.

Impact Analysis

If exploited, this vulnerability allows an attacker with administrator access to execute arbitrary OS commands on the affected device.

  • Complete control over the device's operating system.
  • Potential disruption of network services provided by the device.
  • Possibility of further attacks within the network by leveraging the compromised device.
  • Risk is mitigated somewhat by the requirement for administrative authentication and the default disabling of WAN access.
Compliance Impact

The provided information does not specify how the CVE-2026-1460 vulnerability affects compliance with common standards and regulations such as GDPR or HIPAA.

Mitigation Strategies

The primary mitigation step is to update the affected Zyxel devices to the patched firmware versions provided by Zyxel. Firmware updates address this vulnerability and are either immediately available or scheduled for release.

Additional mitigation includes ensuring strong password management for administrator accounts, as exploitation requires administrative authentication.

Since WAN access is disabled by default on affected devices, limiting remote exploitation, it is also advisable to maintain this default setting and restrict administrative access to trusted networks.

Users who obtained devices through ISPs should contact their ISP support for assistance due to possible custom configurations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-1460. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart