SYS::ONLINE
Wasteland.
Briefs1828
Issues23
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-13206 2026-08-10

Zyxel WAH7601 Hit by Critical Unauthenticated OS Command Injection (CVE-2026-13206)

"A critical OS command injection flaw reported in the Zyxel Networks WAH7601 could allow remote attackers to execute arbitrary commands with no authentication or user interaction, scoring 9.8 on the CVSS 3.1 scale."

A critical OS command injection flaw reported in the Zyxel Networks WAH7601 could allow remote attackers to execute arbitrary commands with no authentication or user interaction, scoring 9.8 on the CVSS 3.1 scale.

What Is It

CVE-2026-13206 is an improper neutralization of special elements used in an OS command, classic OS command injection, tracked as CWE-78, in the Zyxel Networks WAH7601. Special characters supplied to the device are reportedly passed into an OS command context without adequate sanitization, which would allow an attacker to inject and run their own commands.

The vulnerability was published on 2026-08-10 by the Turkish national CERT source (USOM, [email protected]), which is also the assigning CNA for the record. As of this writing the NVD entry remains in Received status, meaning it has not yet completed full NVD analysis and the details below have not been independently validated by NVD.

Why It Matters

The CVSS 3.1 base score is 9.8 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Every exploitability dial is turned to the worst setting: network attack vector, low attack complexity, no privileges required, and no user interaction. The exploitability subscore is a maximum 3.9, with an impact subscore of 5.9 covering high confidentiality, integrity, and availability loss.

In practical terms, if the flaw behaves as described, anyone who can reach the device over the network could potentially take full control of it. There is no CISA KEV entry associated with this CVE in the supplied data, and no public exploit or in-the-wild activity is referenced in the record; active exploitation is not currently confirmed.

What's Vulnerable

No CPE identifiers have been published for this record yet.

Patch Status

The supplied source material does not specify a fixed version, patch, mitigation, or required remediation action. The affected range terminates at 20072026, which implies builds beyond that identifier are not flagged as affected, but no vendor fix advisory is included in the available data. Operators should confirm the advisory details with USOM and Zyxel directly, and restrict network exposure of affected devices pending vendor guidance.

Sources