Junglewise Threat Intelligence

CVE-2026-7256: Zyxel WRE6505 v2 command injection in CGI program

CVE-2026-7256 · Severity: high · CVSS 8.8 · Published 2026-05-12

Technologies: Zyxel Wre6505, Zyxel Wre6505 Firmware. Vendors: Zyxel.

Executive brief

A security vulnerability has been identified in the Zyxel WRE6505 v2, a wireless range extender used to boost WiFi signals. An attacker on the same local network could take complete control of the device by sending a specially crafted web request. Because this product has reached its end-of-life, the manufacturer is not providing a security patch, leaving affected devices permanently vulnerable.

Technical details

A command injection vulnerability (CWE-78) exists within the CGI program of the Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0. The flaw is triggered by insufficient sanitization of input in HTTP requests, allowing an attacker located on the same local area network (LAN) to execute arbitrary operating system commands without authentication. This vulnerability is classified as 'Unsupported When Assigned' because the affected hardware has reached its End-of-Life (EOL) status, and Zyxel has indicated that no further security updates or patches will be released.

Affected products

  • Zyxel WRE6505 v2 V1.00(ABDV.3)C0

Timeline

  • 2026-05-12: disclosed: CVE published and marked as unsupported by vendor

References

Related threats