CVE-2026-1460
published 2026-04-28CVE-2026-1460: A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware…
PriorityP352high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.16%
63.4th percentile
A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | am7510-00_firmware | < 5.63\(acor.0.2\)c0 | 5.63\(acor.0.2\)c0 |
| zyxel | ax7501-b1_firmware | < 5.17\(abpc.7.2\)c0 | 5.17\(abpc.7.2\)c0 |
| zyxel | dx3300-t0_firmware | < 5.50\(abvy.7.2\)c0 | 5.50\(abvy.7.2\)c0 |
| zyxel | dx3300-t1_firmware | < 5.50\(abvy.7.2\)c0 | 5.50\(abvy.7.2\)c0 |
| zyxel | dx3301-t0_firmware | < 5.50\(abvy.7.2\)c0 | 5.50\(abvy.7.2\)c0 |
| zyxel | dx3301-t0_firmware | <= 5.50(ABVY.7.1)C0 | — |
| zyxel | dx5401-b1_firmware | < 5.17\(abyo.7.2\)c0 | 5.17\(abyo.7.2\)c0 |
| zyxel | ee3301-00_firmware | < 5.63\(acmu.3.1\)c0 | 5.63\(acmu.3.1\)c0 |
| zyxel | ee5301-00_firmware | < 5.63\(acld.3.1\)c0 | 5.63\(acld.3.1\)c0 |
| zyxel | ee6510-10_firmware | < 5.19\(acjq.4.2\)c0 | 5.19\(acjq.4.2\)c0 |
| zyxel | emg3525-t50b_firmware | < 5.50\(abpm.9.8\)c0 | 5.50\(abpm.9.8\)c0 |
| zyxel | emg5523-t50b_firmware | < 5.50\(abpm.9.8\)c0 | 5.50\(abpm.9.8\)c0 |
| zyxel | ex2210-t0_firmware | < 5.50\(acdi.2.5\)c0 | 5.50\(acdi.2.5\)c0 |
| zyxel | ex3300-t0_firmware | < 5.50\(abvy.7.2\)c0 | 5.50\(abvy.7.2\)c0 |
| zyxel | ex3300-t1_firmware | < 5.50\(abvy.7.2\)c0 | 5.50\(abvy.7.2\)c0 |
| zyxel | ex3301-t0_firmware | < 5.50\(abvy.7.2\)c0 | 5.50\(abvy.7.2\)c0 |
| zyxel | ex3301-t0_firmware | <= 5.50(ABVY.7.1)C0 | — |
| zyxel | ex3500-t0_firmware | < 5.44\(achr.6\)c0 | 5.44\(achr.6\)c0 |
| zyxel | ex3501-t0_firmware | < 5.44\(achr.6\)c0 | 5.44\(achr.6\)c0 |
| zyxel | ex3600-t0_firmware | < 5.70\(acif.3\)c0 | 5.70\(acif.3\)c0 |
| zyxel | ex5401-b1_firmware | < 5.17\(abyo.7.2\)c0 | 5.17\(abyo.7.2\)c0 |
| zyxel | ex5512-t0_firmware | < 5.70\(aceg.5.5\)c0 | 5.70\(aceg.5.5\)c0 |
| zyxel | ex5601-t0_firmware | < 5.70\(acdz.6\)c0 | 5.70\(acdz.6\)c0 |
| zyxel | ex5601-t1_firmware | < 5.70\(acdz.6\)c0 | 5.70\(acdz.6\)c0 |
| zyxel | ex7501-b0_firmware | < 5.18\(achn.3.2\)c0 | 5.18\(achn.3.2\)c0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cwqh-g98f-v98j: A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 fi
ghsa_unreviewed·2026-04-28
CVE-2026-1460 [HIGH] CWE-78 GHSA-cwqh-g98f-v98j: A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 fi
A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
VulDB
Zyxel DX3301-T0/EX3301-T0 up to 5.50(ABVY.7.1)C0 Configuration File DomainName os command injection (EUVD-2026-25970)
vuldb·2026-04-28·CVSS 7.2
CVE-2026-1460 [HIGH] Zyxel DX3301-T0/EX3301-T0 up to 5.50(ABVY.7.1)C0 Configuration File DomainName os command injection (EUVD-2026-25970)
A vulnerability, which was classified as critical, was found in Zyxel DX3301-T0 and EX3301-T0 up to 5.50(ABVY.7.1)C0. Affected is an unknown function of the component Configuration File Handler. The manipulation of the argument DomainName results in os command injection.
This vulnerability is identified as CVE-2026-1460. The attack can be executed remotely. There is not any exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-28
Published