← לוח פגיעויות

CVE-2026-1460

גבוהה 7.2

תיאור (מקור, אנגלית)

A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

מדדים

CVSS 3.1
7.2 (HIGH) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
1% (אחוזון 100) נכון ל-31/7/2026
CWE
CWE-78

מוצרים מושפעים

zyxel: nebula fwa70 firmware; zyxel: nebula fwa70; zyxel: nebula fwa505 firmware; zyxel: nebula fwa505; zyxel: nebula fwa510 firmware; zyxel: nebula fwa510; zyxel: nebula fwa515 firmware; zyxel: nebula fwa515; zyxel: nebula fwa710 firmware; zyxel: nebula fwa710; zyxel: nebula lte3301-plus firmware; zyxel: nebula lte3301-plus; zyxel: nebula lte7461-m602 firmware; zyxel: nebula lte7461-m602; zyxel: nebula nr5101 firmware

קישורים