• PoC PUBLIC

CVE-2026-6837: authenticated command injection in Zyxel WAX650S firmware

An authenticated administrator can execute arbitrary OS commands on Zyxel WAX650S firmware due to a command injection vulnerability tracked as CVE-2026-6837. The flaw affects WAX650S firmware versions up to and including 7.10(ABRM.4)C0. An attacker requires valid administrator credentials to reach the vulnerable export-cgi component over the device management interface; network access to the device is necessary.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
7.2HIGH
EPSS
0.01521
CWE
CWE-78
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code exists for this post-auth command injection, so prioritize remediation for internet-facing or widely accessible WAX650S devices. Restrict management access immediately and follow vendor guidance while a patch is awaited.

What is CVE-2026-6837?

An authenticated administrator can execute arbitrary OS commands on Zyxel WAX650S firmware due to a command injection vulnerability tracked as CVE-2026-6837. The flaw affects WAX650S firmware versions up to and including 7.10(ABRM.4)C0. An attacker requires valid administrator credentials to reach the vulnerable export-cgi component over the device management interface; network access to the device is necessary. The weakness is classified as CWE-78 (OS Command Injection).

Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Which versions of Zyxel WAX650S firmware are affected?

BRANCHAFFECTEDFIXED
WAX650S firmware<= 7.10(ABRM.4)C0

Is CVE-2026-6837 being exploited?

Public exploit code is available.

How to fix CVE-2026-6837

  1. Restrict management interfaces to trusted networks and block remote access from the internet.
  2. Change and harden administrator credentials and disable unused administrative accounts.
  3. Enable available access controls (IP allowlists, VPN-only management) and monitor device logs for suspicious command executions.
  4. Follow Zyxel vendor advisories and apply firmware updates when Zyxel releases a fixed version.

Frequently asked questions

Is CVE-2026-6837 being actively exploited?

Public exploit code is available for CVE-2026-6837.

Which WAX650S firmware versions are affected by CVE-2026-6837?

WAX650S firmware versions up to and including 7.10(ABRM.4)C0 are affected.

Is there a patch for CVE-2026-6837?

There is no fixed firmware version listed; apply vendor guidance and hardening measures until Zyxel publishes a patch.

Does CVE-2026-6837 require authentication?

Yes. An attacker must have authenticated administrator-level access to exploit the vulnerability in the WAX650S export-cgi component.

References