← All Advisories

Zyxel DX3301-T0 and EX3301-T0 DHCP DomainName parameter command injection allows admin to execute OS commands

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2026-1460

Key Details

CVECVE-2026-1460
CVSS Score / Version7.2 (High) / CVSS v3.1
Updated2026-07-25
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Zyxelnebula_fwa70_firmware
Zyxelnebula_fwa505_firmware
Zyxelnebula_fwa510_firmware
Zyxelnebula_fwa515_firmware
Zyxelnebula_fwa710_firmware
Zyxelnebula_lte3301-plus_firmware
Zyxelnebula_lte7461-m602_firmware
Zyxelnebula_nr5101_firmware
Zyxelnebula_nr7101_firmware
Zyxeldx3300-t0_firmware
Zyxeldx3300-t1_firmware
Zyxeldx3301-t0_firmware
Zyxeldx5401-b1_firmware
Zyxelee3301-00_firmware
Zyxelee5301-00_firmware
Zyxelee6510-10_firmware
Zyxelemg3525-t50b_firmware
Zyxelemg5523-t50b_firmware
Zyxelex2210-t0_firmware
Zyxelex3300-t0_firmware
Zyxelex3300-t1_firmware
Zyxelex3301-t0_firmware
Zyxelex3500-t0_firmware
Zyxelex3501-t0_firmware
Zyxelex3600-t0_firmware
Zyxelex5401-b1_firmware
Zyxelex5512-t0_firmware
Zyxelex5601-t0_firmware
Zyxelex5601-t1_firmware
Zyxelex7501-b0_firmware
Zyxelex7710-b0_firmware
Zyxelgm4100-b0_firmware
Zyxelvmg3625-t50b_firmware
Zyxelvmg4005-b50a_firmware
Zyxelvmg4005-b60a_firmware
Zyxelvmg8623-t50b_firmware
Zyxelam7510-00_firmware
Zyxelax7501-b1_firmware
Zyxelpe3301-00_firmware
Zyxelpe5301-01_firmware
Zyxelpx5301-t0_firmware
Zyxelpx5302-00_firmware
Zyxelwe3300-00_firmware
Zyxelwe4600-00_firmware
Zyxelwx5600-t0_firmware
SubsystemsGeneral OT
SectorsMultiple

What to Know

A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

What to Do

Monitor Zyxel's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-1460
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-1460
Vendor advisoryhttps://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-vulnerabilities-in-certain-4g-lte-5g-nr-cpe-dsl-ethernet-cpe-fiber-onts-and-wireless-extenders-04-28-2026