Command Injection Vulnerability in Zyxel WAX650S Firmware
CVE-2026-6837
Key Information:
- Vendor
Zyxel
- Status
- Vendor
- CVE Published:
- 4 August 2026
Badges
What is CVE-2026-6837?
CVE-2026-6837 is a command injection vulnerability located in the "export-cgi" CGI program of Zyxel WAX650S firmware, specifically affecting versions up to 7.10(ABRM.4)C0. This vulnerability allows authenticated attackers, particularly those with administrator privileges, to execute arbitrary operating system commands on an impacted device. Zyxel WAX650S access points are commonly used in enterprise networking environments, providing wireless connectivity and management capabilities. The consequences of this vulnerability can be severe, leading to unauthorized access to network resources, potential data exfiltration, and compromise of network integrity, as attackers could manipulate the affected device to execute harmful commands or install malicious payloads.
Potential impact of CVE-2026-6837
-
Unauthorized Command Execution: The vulnerability facilitates unauthorized execution of commands on the device, which can lead to complete system compromise. Attackers could leverage this to alter configurations, disrupt services, or gain deeper access into the organization's network infrastructure.
-
Data Breach Risks: By executing commands on a compromised device, attackers could potentially access sensitive data and credentials stored on the device or network, leading to significant risks of data breaches and exposure of confidential information.
-
Network Integrity Compromise: With the ability to control the affected device, attackers could manipulate network traffic, create backdoors, or deploy malware across the network, severely compromising the integrity and security of the entire organizational network.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WAX650S firmware <= 7.10(ABRM.4)C0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.