A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS commands on an affected device.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 28 Apr 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Zyxel
Zyxel dx3300-t0 Firmware
Vendors & Products Zyxel
Zyxel dx3300-t0 Firmware

Tue, 28 Apr 2026 03:00:00 +0000

Type Values Removed Values Added
Description A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS commands on an affected device.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published:

Updated: 2026-04-28T01:57:54.011Z

Reserved: 2026-01-08T08:42:15.633Z

Link: CVE-2026-0711

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-28T03:16:02.167

Modified: 2026-04-28T03:16:02.167

Link: CVE-2026-0711

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T04:30:20Z

Weaknesses