cbcvebase.
CVE-2026-1460
published 2026-04-28

CVE-2026-1460: A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware…

PriorityP352high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.16%
63.4th percentile
A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
zyxelam7510-00_firmware< 5.63\(acor.0.2\)c05.63\(acor.0.2\)c0
zyxelax7501-b1_firmware< 5.17\(abpc.7.2\)c05.17\(abpc.7.2\)c0
zyxeldx3300-t0_firmware< 5.50\(abvy.7.2\)c05.50\(abvy.7.2\)c0
zyxeldx3300-t1_firmware< 5.50\(abvy.7.2\)c05.50\(abvy.7.2\)c0
zyxeldx3301-t0_firmware< 5.50\(abvy.7.2\)c05.50\(abvy.7.2\)c0
zyxeldx3301-t0_firmware<= 5.50(ABVY.7.1)C0
zyxeldx5401-b1_firmware< 5.17\(abyo.7.2\)c05.17\(abyo.7.2\)c0
zyxelee3301-00_firmware< 5.63\(acmu.3.1\)c05.63\(acmu.3.1\)c0
zyxelee5301-00_firmware< 5.63\(acld.3.1\)c05.63\(acld.3.1\)c0
zyxelee6510-10_firmware< 5.19\(acjq.4.2\)c05.19\(acjq.4.2\)c0
zyxelemg3525-t50b_firmware< 5.50\(abpm.9.8\)c05.50\(abpm.9.8\)c0
zyxelemg5523-t50b_firmware< 5.50\(abpm.9.8\)c05.50\(abpm.9.8\)c0
zyxelex2210-t0_firmware< 5.50\(acdi.2.5\)c05.50\(acdi.2.5\)c0
zyxelex3300-t0_firmware< 5.50\(abvy.7.2\)c05.50\(abvy.7.2\)c0
zyxelex3300-t1_firmware< 5.50\(abvy.7.2\)c05.50\(abvy.7.2\)c0
zyxelex3301-t0_firmware< 5.50\(abvy.7.2\)c05.50\(abvy.7.2\)c0
zyxelex3301-t0_firmware<= 5.50(ABVY.7.1)C0
zyxelex3500-t0_firmware< 5.44\(achr.6\)c05.44\(achr.6\)c0
zyxelex3501-t0_firmware< 5.44\(achr.6\)c05.44\(achr.6\)c0
zyxelex3600-t0_firmware< 5.70\(acif.3\)c05.70\(acif.3\)c0
zyxelex5401-b1_firmware< 5.17\(abyo.7.2\)c05.17\(abyo.7.2\)c0
zyxelex5512-t0_firmware< 5.70\(aceg.5.5\)c05.70\(aceg.5.5\)c0
zyxelex5601-t0_firmware< 5.70\(acdz.6\)c05.70\(acdz.6\)c0
zyxelex5601-t1_firmware< 5.70\(acdz.6\)c05.70\(acdz.6\)c0
zyxelex7501-b0_firmware< 5.18\(achn.3.2\)c05.18\(achn.3.2\)c0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.