Executive brief
Zyxel WAX650S is a wireless access point used to provide network connectivity in enterprise and business environments. A post-authentication command injection flaw in the device's export-cgi program allows authenticated administrators to execute arbitrary operating system commands, potentially enabling unauthorized system takeover or data theft. This vulnerability requires administrator credentials to exploit but grants an attacker full control over the affected device.
Technical details
The vulnerability is a post-authentication command injection flaw in the "export-cgi" CGI program. An authenticated attacker with administrator privileges can inject OS commands that are executed on the device. The vulnerability affects Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0. Attack requires valid administrator credentials to authenticate to the device. Successful exploitation allows an attacker to execute arbitrary OS commands with device privileges, potentially leading to full compromise. Patches are available in firmware version 7.12 and later.
Affected products
- Zyxel WAX650S through 7.10(ABRM.4)C0
Timeline
- 2026-08-04: disclosed
- 2026-08-04: patched: Patches available in firmware 7.12 and later