CVE-2026-7256: OS Command Injection
UNSUPPORTED WHEN ASSIGNED A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to execute operating system (OS) commands on a vulnerable device by sending a crafted HTTP request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zyxel WRE6505 v2 firmwareto a version that resolves this vulnerability.Fixed in V1.00(ABDV.3)C0 - Compensating control
Restrict network access to the Zyxel WRE6505 v2 CGI interface from the LAN (e.g., via firewall/ACL) to prevent adjacent attackers from sending crafted HTTP requests to the vulnerable CGI program.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7256?
CVE-2026-7256 has a high severity level due to its potential to allow command injection by adjacent attackers.
How do I fix CVE-2026-7256?
The recommended fix for CVE-2026-7256 is to upgrade or replace the Zyxel WRE6505 v2 firmware, if available, or to mitigate access to vulnerable devices.
What does CVE-2026-7256 affect?
CVE-2026-7256 affects the Zyxel WRE6505 v2 firmware, specifically version V1.00(ABDV.3)C0.
Can CVE-2026-7256 be exploited remotely?
CVE-2026-7256 requires an adjacent attacker on the LAN to exploit the command injection vulnerability.
Is there a patch for CVE-2026-7256?
As CVE-2026-7256 is marked as unsupported when assigned, there may not be an official patch available.