Improper Encoding Vulnerability in Zyxel WRE6505 Wireless Extender
CVE-2026-6058

4.5MEDIUM

Key Information:

Vendor

Zyxel

Vendor
CVE Published:
21 April 2026

What is CVE-2026-6058?

An improper encoding or escaping vulnerability exists in the CGI program of Zyxel WRE6505 v2 firmware. This flaw can be exploited by an adjacent attacker on the WLAN by persuading an authenticated administrator to access the 'AP Select' page while a malformed SSID is present, potentially leading to a denial-of-service (DoS) condition in the web management interface.

Affected Version(s)

WRE6505 v2 firmware V1.00(ABDV.3)C0

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.