CVE-2026-7287

** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert() functions of the “webs” binary in Zyxel NWA1100-N customized firmware version 1.00(AACE.1)C0 could allow an attacker to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request to a vulnerable device.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zyxel:nwa1100-n_firmware:1.00\(aace.1\)c0:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:nwa1100-n:-:*:*:*:*:*:*:*

History

16 May 2026, 03:08

Type Values Removed Values Added
First Time Zyxel nwa1100-n Firmware
Zyxel
Zyxel nwa1100-n
CPE cpe:2.3:o:zyxel:nwa1100-n_firmware:1.00\(aace.1\)c0:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:nwa1100-n:-:*:*:*:*:*:*:*
References () https://www.zyxel.com/global/en/support/end-of-life - () https://www.zyxel.com/global/en/support/end-of-life - Product

12 May 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-12 04:16

Updated : 2026-05-16 03:08


NVD link : CVE-2026-7287

Mitre link : CVE-2026-7287

CVE.ORG link : CVE-2026-7287


JSON object : View

Products Affected

zyxel

  • nwa1100-n
  • nwa1100-n_firmware
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')