A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on an affected device.
Metrics
Affected Vendors & Products
History
Wed, 25 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zyxel dx5401-b1
Zyxel dx5401-b1 Firmware Zyxel emg3525-t50b Zyxel emg3525-t50b Firmware Zyxel emg5523-t50b Zyxel emg5523-t50b Firmware Zyxel vmg3625-t50b Zyxel vmg3625-t50c Zyxel vmg3625-t50c Firmware Zyxel vmg8623-t50b Zyxel vmg8623-t50b Firmware |
|
| CPEs | cpe:2.3:h:zyxel:dx5401-b1:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:emg3525-t50b:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:emg5523-t50b:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg3625-t50b:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg3625-t50c:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg8623-t50b:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:dx5401-b1_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:emg3525-t50b_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:emg5523-t50b_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg3625-t50b_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg3625-t50c_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg8623-t50b_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Zyxel dx5401-b1
Zyxel dx5401-b1 Firmware Zyxel emg3525-t50b Zyxel emg3525-t50b Firmware Zyxel emg5523-t50b Zyxel emg5523-t50b Firmware Zyxel vmg3625-t50b Zyxel vmg3625-t50c Zyxel vmg3625-t50c Firmware Zyxel vmg8623-t50b Zyxel vmg8623-t50b Firmware |
Tue, 24 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Feb 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zyxel
Zyxel vmg3625-t50b Firmware |
|
| Vendors & Products |
Zyxel
Zyxel vmg3625-t50b Firmware |
Tue, 24 Feb 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on an affected device. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zyxel
Published: 2026-02-24T02:48:35.439Z
Updated: 2026-02-25T04:55:34.749Z
Reserved: 2026-01-27T01:26:24.186Z
Link: CVE-2026-1459
Updated: 2026-02-24T19:18:43.312Z
Status : Analyzed
Published: 2026-02-24T03:16:00.587
Modified: 2026-02-25T18:05:40.307
Link: CVE-2026-1459
No data.