Executive brief
A security vulnerability exists in several Zyxel networking devices, including routers and extenders, that could allow an attacker to take full control of the device. To exploit this, an attacker must already have administrator-level access and be located on the same local network. If successful, the attacker could execute unauthorized commands, potentially leading to data theft or disruption of network services.
Technical details
This vulnerability (CWE-78) is a post-authentication command injection flaw located within the EasyMesh-related APIs of Zyxel firmware. The issue stems from improper neutralization of special elements used in OS commands. An attacker requires administrator-level privileges and must be positioned on an adjacent network (local network) to reach the vulnerable API. Successful exploitation allows for arbitrary OS command execution on the underlying operating system. Zyxel has released firmware patches (e.g., version 5.50(ABVY.7.2)C0 for the DX3300-T0) to address this issue across multiple product lines including 4G/5G CPE, DSL/Ethernet CPE, and Fiber ONTs.
Affected products
- Zyxel NR5307 through 2.00(ACJT.1)C0
- Zyxel Nebula FWA515 through 1.60(ACPZ.0)C0
- Zyxel DX3300-T0 through 5.50(ABVY.7.1)C0
- Zyxel DX3300-T1 through 5.50(ABVY.7.1)C0
- Zyxel DX3301-T0 through 5.50(ABVY.7.1)C0
- Zyxel DX5401-B0 through 5.17(ABYO.7.1)C0
- Zyxel DX5401-B1 through 5.17(ABYO.7.1)C0
- Zyxel EE3301-00 through 5.63(ACMU.2.1)C0
- Zyxel EE5301-00 through 5.63(ACLD.2.1)C0
- Zyxel EE6510-10 through 5.19(ACJQ.4.1)C0
- Zyxel EMG3525-T50B through 5.50(ABPM.9.7)C0
- Zyxel EMG5523-T50B through 5.50(ABPM.9.7)C0
- Zyxel EX3300-T0 through 5.50(ABVY.7.1)C0
- Zyxel EX3300-T1 through 5.50(ABVY.7.1)C0
- Zyxel EX3301-T0 through 5.50(ABVY.7.1)C0
- Zyxel EX3500-T0 through 5.44(ACHR.5.1)C0
- Zyxel EX3501-T0 through 5.44(ACHR.5.1)C0
- Zyxel EX3600-T0 through 5.70(ACIF.2.1)C0
- Zyxel EX5401-B0 through 5.17(ABYO.7.1)C0
- Zyxel EX5401-B1 through 5.17(ABYO.7.1)C0
- Zyxel EX5512-T0 through 5.70(ACEG.5.4)C0
- Zyxel EX5601-T0 through 5.70(ACDZ.5.1)C0
- Zyxel EX5601-T1 through 5.70(ACDZ.5.1)C0
- Zyxel EX7501-B0 through 5.18(ACHN.3.1)C0
- Zyxel VMG3625-T50B through 5.50(ABPM.9.7)C0
- Zyxel VMG8623-T50B through 5.50(ABPM.9.7)C0
- Zyxel AX7501-B0 through 5.17(ABPC.7.1)C0
- Zyxel AX7501-B1 through 5.17(ABPC.7.1)C0
- Zyxel PE3301-00 through 5.63(ACMT.2.1)C0
- Zyxel PE5301-01 through 5.63(ACOJ.2.1)C0
Timeline
- 2026-04-28: advisory: Zyxel published the security advisory.
- 2026-04-28: patched: Patches released for most affected models.