A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on an affected device.
References
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
History
25 Feb 2026, 18:05
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| References | () https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-null-pointer-dereference-and-command-injection-vulnerabilities-in-certain-4g-lte-5g-nr-cpe-dsl-ethernet-cpe-fiber-onts-security-routers-and-wireless-extenders-02-24-2026 - Vendor Advisory | |
| CPE | cpe:2.3:h:zyxel:emg3525-t50b:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg3625-t50b_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg3625-t50c:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg8623-t50b_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:emg5523-t50b:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:emg3525-t50b_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg3625-t50c_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg3625-t50b:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg8623-t50b:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:dx5401-b1:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:emg5523-t50b_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:dx5401-b1_firmware:*:*:*:*:*:*:*:* |
|
| First Time |
Zyxel vmg3625-t50b
Zyxel vmg3625-t50b Firmware Zyxel dx5401-b1 Zyxel dx5401-b1 Firmware Zyxel emg3525-t50b Zyxel vmg8623-t50b Zyxel emg5523-t50b Zyxel vmg8623-t50b Firmware Zyxel Zyxel emg3525-t50b Firmware Zyxel emg5523-t50b Firmware Zyxel vmg3625-t50c Firmware Zyxel vmg3625-t50c |
24 Feb 2026, 03:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-24 03:16
Updated : 2026-02-25 18:05
NVD link : CVE-2026-1459
Mitre link : CVE-2026-1459
CVE.ORG link : CVE-2026-1459
JSON object : View
Products Affected
zyxel
- vmg3625-t50b_firmware
- vmg3625-t50c_firmware
- dx5401-b1
- emg5523-t50b
- emg5523-t50b_firmware
- emg3525-t50b_firmware
- vmg8623-t50b
- vmg3625-t50c
- emg3525-t50b
- vmg8623-t50b_firmware
- vmg3625-t50b
- dx5401-b1_firmware
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
