Description

A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

INFO

Published Date :

2026-04-28T02:06:22.568Z

Last Modified :

2026-04-29T03:55:38.320Z

Source :

Zyxel
AFFECTED PRODUCTS

The following products are affected by CVE-2026-1460 vulnerability.

Vendors Products
Zyxel
  • Dx3301-t0 Firmware
  • Ex3301-t0 Firmware

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact