A
post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on an affected device.
References
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
History
25 Feb 2026, 18:05
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-null-pointer-dereference-and-command-injection-vulnerabilities-in-certain-4g-lte-5g-nr-cpe-dsl-ethernet-cpe-fiber-onts-security-routers-and-wireless-extenders-02-24-2026 - Vendor Advisory | |
| First Time |
Zyxel dx5401-b1 Firmware
Zyxel emg5523-t50b Zyxel vmg3625-t50b Firmware Zyxel vmg3625-t50c Zyxel vmg3625-t50c Firmware Zyxel Zyxel dx5401-b1 Zyxel emg3525-t50b Zyxel vmg8623-t50b Firmware Zyxel emg5523-t50b Firmware Zyxel vmg3625-t50b Zyxel vmg8623-t50b Zyxel emg3525-t50b Firmware |
|
| CPE | cpe:2.3:h:zyxel:emg5523-t50b:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:dx5401-b1_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg3625-t50b:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg3625-t50b_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg3625-t50c:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:dx5401-b1:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:emg3525-t50b_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:emg3525-t50b:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg3625-t50c_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg8623-t50b_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:emg5523-t50b_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg8623-t50b:-:*:*:*:*:*:*:* |
|
| Summary |
|
24 Feb 2026, 03:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-24 03:16
Updated : 2026-02-25 18:05
NVD link : CVE-2026-1459
Mitre link : CVE-2026-1459
CVE.ORG link : CVE-2026-1459
JSON object : View
Products Affected
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')