CVE-2026-1460High· 7.2▾ TwilightA post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with adm…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.2%
A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
nebula_fwa70_firmware < 1.51\(acrf.0\)v0nebula_fwa505_firmware < 1.60\(acko.3\)v0nebula_fwa510_firmware < 1.60\(acgd.1\)v0nebula_fwa515_firmware < 1.60\(acpz.1\)v0nebula_fwa710_firmware < 1.60\(acgc.2\)v0nebula_lte3301-plus_firmware < 1.18\(acca.7\)v0nebula_lte7461-m602_firmware < 1.15\(acev.4\)v0nebula_nr5101_firmware < 1.16\(accg.1\)v0nebula_nr7101_firmware < 1.16\(accc.2\)v0dx3300-t0_firmware < 5.50\(abvy.7.2\)c0dx3300-t1_firmware < 5.50\(abvy.7.2\)c0dx3301-t0_firmware < 5.50\(abvy.7.2\)c0dx5401-b1_firmware < 5.17\(abyo.7.2\)c0ee3301-00_firmware < 5.63\(acmu.3.1\)c0ee5301-00_firmware < 5.63\(acld.3.1\)c0ee6510-10_firmware < 5.19\(acjq.4.2\)c0emg3525-t50b_firmware < 5.50\(abpm.9.8\)c0emg5523-t50b_firmware < 5.50\(abpm.9.8\)c0ex2210-t0_firmware < 5.50\(acdi.2.5\)c0ex3300-t0_firmware < 5.50\(abvy.7.2\)c0ex3300-t1_firmware < 5.50\(abvy.7.2\)c0ex3301-t0_firmware < 5.50\(abvy.7.2\)c0ex3500-t0_firmware < 5.44\(achr.6\)c0ex3501-t0_firmware < 5.44\(achr.6\)c0ex3600-t0_firmware < 5.70\(acif.3\)c0ex5401-b1_firmware < 5.17\(abyo.7.2\)c0ex5512-t0_firmware < 5.70\(aceg.5.5\)c0ex5601-t0_firmware < 5.70\(acdz.6\)c0ex5601-t1_firmware < 5.70\(acdz.6\)c0ex7501-b0_firmware < 5.18\(achn.3.2\)c0ex7710-b0_firmware < 5.18\(acak.1.7\)c0gm4100-b0_firmware < 5.18\(accl.2.1\)c0vmg3625-t50b_firmware < 5.50\(abpm.9.8\)c0vmg4005-b50a_firmware < 5.17\(abqa.3.3\)c0vmg4005-b60a_firmware < 5.17\(abqa.3.3\)c0vmg8623-t50b_firmware < 5.50\(abpm.9.8\)c0am7510-00_firmware < 5.63\(acor.0.2\)c0ax7501-b1_firmware < 5.17\(abpc.7.2\)c0pe3301-00_firmware < 5.63\(acmt.3.1\)c0pe5301-01_firmware < 5.63\(acoj.3.1\)c0px5301-t0_firmware < 5.44\(ackb.0.7\)c0px5302-00_firmware < 5.44\(acnm.0.1\)c0we3300-00_firmware < 5.70\(acka.2\)c0we4600-00_firmware < 6.70\(ackt.1\)c0wx5600-t0_firmware < 5.70\(aceb.6\)c0Upgrade past the affected range:
nebula_fwa70_firmware 1.51\(acrf.0\)v0nebula_fwa505_firmware 1.60\(acko.3\)v0nebula_fwa510_firmware 1.60\(acgd.1\)v0nebula_fwa515_firmware 1.60\(acpz.1\)v0nebula_fwa710_firmware 1.60\(acgc.2\)v0nebula_lte3301-plus_firmware 1.18\(acca.7\)v0nebula_lte7461-m602_firmware 1.15\(acev.4\)v0nebula_nr5101_firmware 1.16\(accg.1\)v0nebula_nr7101_firmware 1.16\(accc.2\)v0dx3300-t0_firmware 5.50\(abvy.7.2\)c0dx3300-t1_firmware 5.50\(abvy.7.2\)c0dx3301-t0_firmware 5.50\(abvy.7.2\)c0dx5401-b1_firmware 5.17\(abyo.7.2\)c0ee3301-00_firmware 5.63\(acmu.3.1\)c0ee5301-00_firmware 5.63\(acld.3.1\)c0ee6510-10_firmware 5.19\(acjq.4.2\)c0emg3525-t50b_firmware 5.50\(abpm.9.8\)c0emg5523-t50b_firmware 5.50\(abpm.9.8\)c0ex2210-t0_firmware 5.50\(acdi.2.5\)c0ex3300-t0_firmware 5.50\(abvy.7.2\)c0ex3300-t1_firmware 5.50\(abvy.7.2\)c0ex3301-t0_firmware 5.50\(abvy.7.2\)c0ex3500-t0_firmware 5.44\(achr.6\)c0ex3501-t0_firmware 5.44\(achr.6\)c0ex3600-t0_firmware 5.70\(acif.3\)c0ex5401-b1_firmware 5.17\(abyo.7.2\)c0ex5512-t0_firmware 5.70\(aceg.5.5\)c0ex5601-t0_firmware 5.70\(acdz.6\)c0ex5601-t1_firmware 5.70\(acdz.6\)c0ex7501-b0_firmware 5.18\(achn.3.2\)c0ex7710-b0_firmware 5.18\(acak.1.7\)c0gm4100-b0_firmware 5.18\(accl.2.1\)c0vmg3625-t50b_firmware 5.50\(abpm.9.8\)c0vmg4005-b50a_firmware 5.17\(abqa.3.3\)c0vmg4005-b60a_firmware 5.17\(abqa.3.3\)c0vmg8623-t50b_firmware 5.50\(abpm.9.8\)c0am7510-00_firmware 5.63\(acor.0.2\)c0ax7501-b1_firmware 5.17\(abpc.7.2\)c0pe3301-00_firmware 5.63\(acmt.3.1\)c0pe5301-01_firmware 5.63\(acoj.3.1\)c0px5301-t0_firmware 5.44\(ackb.0.7\)c0px5302-00_firmware 5.44\(acnm.0.1\)c0we3300-00_firmware 5.70\(acka.2\)c0we4600-00_firmware 6.70\(ackt.1\)c0wx5600-t0_firmware 5.70\(aceb.6\)c0Connected by shared product, vendor, weakness, or advisory.
CVE-2017-6884High· 8.8A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8
CVE-2026-0711Medium· 6.8A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS …
CVE-2018-11138Critical· 9.8The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
CVE-2020-3167High· 7.8A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS)
CVE-2019-1709Medium· 6.0A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack
CVE-2024-51378Critical· 10.0getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…