CVE-2026-1459
HIGHZyxel VMG3625-T50B <5.50(ABPM.9.7)C0 - Command Injection
Title source: llmDescription
A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on an affected device.
Exploits (1)
Scores
CVSS v3
7.2
EPSS
0.0003
EPSS Percentile
7.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (6)
zyxel/dx5401-b1_firmware
< 5.17\(abyo.7.1\)c0
zyxel/emg3525-t50b_firmware
< 5.50\(abpm.9.7\)c0
zyxel/emg5523-t50b_firmware
< 5.50\(abpm.9.7\)c0
zyxel/vmg3625-t50b_firmware
< 5.50\(abpm.9.7\)c0
zyxel/vmg3625-t50c_firmware
< 5.50\(abpm.9.7\)c0
zyxel/vmg8623-t50b_firmware
< 5.50\(abpm.9.7\)c0
Published
Feb 24, 2026
Tracked Since
Feb 24, 2026