Zyxel Patches Command Injection Flaw in 18 Access Points Allowing Root OS Command Execution

Zyxel has released firmware updates for a high-severity command injection vulnerability, tracked as CVE-2026-6837, affecting 18 wireless access point models. The flaw exists in the export-cgi component and could allow an authenticated administrator to execute operating-system commands on vulnerable devices. The issue affects the PKCS#12 certificate export workflow. Security researcher Mina Nageh Salama reported that the certificate […]

This article has been indexed from Cyber Security News

Read the original article: