DIRAS TAKE
Urgent: public exploit code exists for this post-auth command injection, so prioritize remediation for internet-facing or widely accessible WAX650S devices. Restrict management access immediately and follow vendor guidance while a patch is awaited.
What is CVE-2026-6837?
An authenticated administrator can execute arbitrary OS commands on Zyxel WAX650S firmware due to a command injection vulnerability tracked as CVE-2026-6837. The flaw affects WAX650S firmware versions up to and including 7.10(ABRM.4)C0. An attacker requires valid administrator credentials to reach the vulnerable export-cgi component over the device management interface; network access to the device is necessary. The weakness is classified as CWE-78 (OS Command Injection).
Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Which versions of Zyxel WAX650S firmware are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| WAX650S firmware | <= 7.10(ABRM.4)C0 |
Is CVE-2026-6837 being exploited?
Public exploit code is available.
How to fix CVE-2026-6837
- Restrict management interfaces to trusted networks and block remote access from the internet.
- Change and harden administrator credentials and disable unused administrative accounts.
- Enable available access controls (IP allowlists, VPN-only management) and monitor device logs for suspicious command executions.
- Follow Zyxel vendor advisories and apply firmware updates when Zyxel releases a fixed version.
Frequently asked questions
Is CVE-2026-6837 being actively exploited?
Public exploit code is available for CVE-2026-6837.
Which WAX650S firmware versions are affected by CVE-2026-6837?
WAX650S firmware versions up to and including 7.10(ABRM.4)C0 are affected.
Is there a patch for CVE-2026-6837?
There is no fixed firmware version listed; apply vendor guidance and hardening measures until Zyxel publishes a patch.
Does CVE-2026-6837 require authentication?
Yes. An attacker must have authenticated administrator-level access to exploit the vulnerability in the WAX650S export-cgi component.
References
- nvd.nist.gov/vuln/detail/CVE-2026-6837
- cve.org/CVERecord?id=CVE-2026-6837
- zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026
- All Zyxel CVEs on CVE Radar
- CVEs published in September 2026