HIGH · 7.2

CVE-2026-1460

A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could all...

Vulnerability Description

A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

CVSS Score

7.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ZyxelNebula Fwa70 Firmware< 1.51\(acrf.0\)v0
ZyxelNebula Fwa70-
ZyxelNebula Fwa505 Firmware< 1.60\(acko.3\)v0
ZyxelNebula Fwa505-
ZyxelNebula Fwa510 Firmware< 1.60\(acgd.1\)v0
ZyxelNebula Fwa510-
ZyxelNebula Fwa515 Firmware< 1.60\(acpz.1\)v0
ZyxelNebula Fwa515-
ZyxelNebula Fwa710 Firmware< 1.60\(acgc.2\)v0
ZyxelNebula Fwa710-
ZyxelNebula Lte3301-Plus Firmware< 1.18\(acca.7\)v0
ZyxelNebula Lte3301-Plus-
ZyxelNebula Lte7461-M602 Firmware< 1.15\(acev.4\)v0
ZyxelNebula Lte7461-M602-
ZyxelNebula Nr5101 Firmware< 1.16\(accg.1\)v0
ZyxelNebula Nr5101-
ZyxelNebula Nr7101 Firmware< 1.16\(accc.2\)v0
ZyxelNebula Nr7101-
ZyxelDx3300-T0 Firmware< 5.50\(abvy.7.2\)c0
ZyxelDx3300-T0-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-1460?

CVE-2026-1460 is a vulnerability with a CVSS score of 7.2 (HIGH). A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could all...

How severe is CVE-2026-1460?

CVE-2026-1460 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-1460?

Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Nebula Fwa70 Firmware, Zyxel Nebula Fwa70, Zyxel Nebula Fwa505 Firmware, Zyxel Nebula Fwa505, Zyxel Nebula Fwa510 Firmware.