Junglewise Threat Intelligence

CVE-2026-1460: Zyxel multiple CPE and ONT devices command injection in DHCP DomainName

CVE-2026-1460 · Severity: high · CVSS 7.2 · Published 2026-04-28

Vendors: Zyxel.

Executive brief

A security vulnerability has been identified in several Zyxel networking devices, including various 4G/5G routers and fiber modems. An attacker who has already obtained administrative credentials could use this flaw to take full control of the device's operating system. While the risk is mitigated by the fact that remote management is disabled by default, a successful exploit could lead to complete service disruption or unauthorized monitoring of network traffic.

Technical details

This vulnerability is classified as an OS command injection (CWE-78) within the DHCP configuration component of various Zyxel firmware versions. The flaw exists in the handling of the 'DomainName' parameter. An attacker with valid administrator-level credentials can inject malicious commands into the configuration file, which are subsequently executed by the underlying operating system. The attack vector is network-based, though Zyxel notes that WAN access is typically disabled by default. Successful exploitation results in full system compromise (High Confidentiality, Integrity, and Availability impact). Patches have been released for most affected models, with some scheduled for May 2026.

Affected products

  • Zyxel DX3300-T0 firmware up to 5.50(ABVY.7.1)C0
  • Zyxel DX3301-T0 firmware up to 5.50(ABVY.7.1)C0
  • Zyxel EX3300-T0 firmware up to 5.50(ABVY.7.1)C0
  • Zyxel EX3301-T0 firmware up to 5.50(ABVY.7.1)C0
  • Zyxel AX7501-B1 firmware up to 5.17(ABPC.7.1)C0
  • Zyxel EMG3525-T50B firmware up to 5.50(ABPM.9.7)C0
  • Zyxel EX5601-T0 firmware up to 5.70(ACDZ.5.1)C0

Timeline

  • 2026-04-28: advisory: Zyxel published the security advisory.
  • 2026-04-28: patched: Initial patches released for several models.

References