Executive brief
The Zyxel WAH7601 is a wireless access point used to provide network connectivity in corporate and public environments. An OS command injection vulnerability allows remote attackers to execute arbitrary system commands on the device, potentially leading to complete compromise of the access point, unauthorized network access, and lateral movement to connected networks.
Technical details
The vulnerability is an OS command injection flaw in the WAH7601 wireless access point, caused by improper neutralization of special characters used in operating system commands. The vulnerability is remotely exploitable without authentication required, as indicated by the CVSS 9.8 score and attack vector classification. An attacker can craft malicious input to the device that breaks out of intended command boundaries and execute arbitrary OS-level commands with the privileges of the access point process. This grants full control over the device, allowing attacker to modify configurations, intercept traffic, or use it as a pivot point for network attacks.
Affected products
- Zyxel WAH7601 through 20072026
Timeline
- 2026-08-10: disclosed