Vulnerability Description
A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | Nebula Fwa70 Firmware | < 1.51\(acrf.0\)v0 |
| Zyxel | Nebula Fwa70 | - |
| Zyxel | Nebula Fwa505 Firmware | < 1.60\(acko.3\)v0 |
| Zyxel | Nebula Fwa505 | - |
| Zyxel | Nebula Fwa510 Firmware | < 1.60\(acgd.1\)v0 |
| Zyxel | Nebula Fwa510 | - |
| Zyxel | Nebula Fwa515 Firmware | < 1.60\(acpz.1\)v0 |
| Zyxel | Nebula Fwa515 | - |
| Zyxel | Nebula Fwa710 Firmware | < 1.60\(acgc.2\)v0 |
| Zyxel | Nebula Fwa710 | - |
| Zyxel | Nebula Lte3301-Plus Firmware | < 1.18\(acca.7\)v0 |
| Zyxel | Nebula Lte3301-Plus | - |
| Zyxel | Nebula Lte7461-M602 Firmware | < 1.15\(acev.4\)v0 |
| Zyxel | Nebula Lte7461-M602 | - |
| Zyxel | Nebula Nr5101 Firmware | < 1.16\(accg.1\)v0 |
| Zyxel | Nebula Nr5101 | - |
| Zyxel | Nebula Nr7101 Firmware | < 1.16\(accc.2\)v0 |
| Zyxel | Nebula Nr7101 | - |
| Zyxel | Dx3300-T0 Firmware | < 5.50\(abvy.7.2\)c0 |
| Zyxel | Dx3300-T0 | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-1460?
CVE-2026-1460 is a vulnerability with a CVSS score of 7.2 (HIGH). A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could all...
How severe is CVE-2026-1460?
CVE-2026-1460 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-1460?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Nebula Fwa70 Firmware, Zyxel Nebula Fwa70, Zyxel Nebula Fwa505 Firmware, Zyxel Nebula Fwa505, Zyxel Nebula Fwa510 Firmware.