Vulnerability Description
A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS commands on an affected device.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | Nr5307 Firmware | < 2.00\(acjt.3\)c0 |
| Zyxel | Nr5307 | - |
| Zyxel | Nebula Fwa515 Firmware | < 1.60\(acpz.0\)v0 |
| Zyxel | Nebula Fwa515 | - |
| Zyxel | Dx3300-T0 Firmware | < 5.50\(abvy.7.2\)c0 |
| Zyxel | Dx3300-T0 | - |
| Zyxel | Dx3300-T1 Firmware | < 5.50\(abvy.7.2\)c0 |
| Zyxel | Dx3300-T1 | - |
| Zyxel | Dx3301-T0 Firmware | < 5.50\(abvy.7.2\)c0 |
| Zyxel | Dx3301-T0 | - |
| Zyxel | Dx5401-B0 Firmware | < 5.17\(abyo.7.2\)c0 |
| Zyxel | Dx5401-B0 | - |
| Zyxel | Dx5401-B1 Firmware | < 5.17\(abyo.7.2\)c0 |
| Zyxel | Dx5401-B1 | - |
| Zyxel | Ee3301-00 Firmware | < 5.63\(acmu.3.1\)c0 |
| Zyxel | Ee3301-00 | - |
| Zyxel | Ee5301-00 Firmware | < 5.63\(acld.3.1\)c0 |
| Zyxel | Ee5301-00 | - |
| Zyxel | Ee6510-10 Firmware | < 5.19\(acjq.4.2\)c0 |
| Zyxel | Ee6510-10 | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-0711?
CVE-2026-0711 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with ad...
How severe is CVE-2026-0711?
CVE-2026-0711 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-0711?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Nr5307 Firmware, Zyxel Nr5307, Zyxel Nebula Fwa515 Firmware, Zyxel Nebula Fwa515, Zyxel Dx3300-T0 Firmware.