Description

A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on an affected device.

INFO

Published Date :

2026-02-24T02:48:35.439Z

Last Modified :

2026-02-26T14:44:10.011Z

Source :

Zyxel
AFFECTED PRODUCTS

The following products are affected by CVE-2026-1459 vulnerability.

Vendors Products
Zyxel
  • Dx5401-b1
  • Dx5401-b1 Firmware
  • Emg3525-t50b
  • Emg3525-t50b Firmware
  • Emg5523-t50b
  • Emg5523-t50b Firmware
  • Vmg3625-t50b
  • Vmg3625-t50b Firmware
  • Vmg3625-t50c
  • Vmg3625-t50c Firmware
  • Vmg8623-t50b
  • Vmg8623-t50b Firmware

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact