A critical OS command injection flaw reported in the Zyxel Networks WAH7601 could allow remote attackers to execute arbitrary commands with no authentication or user interaction, scoring 9.8 on the CVSS 3.1 scale.
What Is It
CVE-2026-13206 is an improper neutralization of special elements used in an OS command, classic OS command injection, tracked as CWE-78, in the Zyxel Networks WAH7601. Special characters supplied to the device are reportedly passed into an OS command context without adequate sanitization, which would allow an attacker to inject and run their own commands.
The vulnerability was published on 2026-08-10 by the Turkish national CERT source (USOM, [email protected]), which is also the assigning CNA for the record. As of this writing the NVD entry remains in Received status, meaning it has not yet completed full NVD analysis and the details below have not been independently validated by NVD.
Why It Matters
The CVSS 3.1 base score is 9.8 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Every exploitability dial is turned to the worst setting: network attack vector, low attack complexity, no privileges required, and no user interaction. The exploitability subscore is a maximum 3.9, with an impact subscore of 5.9 covering high confidentiality, integrity, and availability loss.
In practical terms, if the flaw behaves as described, anyone who can reach the device over the network could potentially take full control of it. There is no CISA KEV entry associated with this CVE in the supplied data, and no public exploit or in-the-wild activity is referenced in the record; active exploitation is not currently confirmed.
What's Vulnerable
- Vendor: Zyxel Networks
- Product: WAH7601
- Affected versions: all versions from
0through20072026(custom version scheme, less-than-or-equal) - Default status for other versions: unaffected
No CPE identifiers have been published for this record yet.
Patch Status
The supplied source material does not specify a fixed version, patch, mitigation, or required remediation action. The affected range terminates at 20072026, which implies builds beyond that identifier are not flagged as affected, but no vendor fix advisory is included in the available data. Operators should confirm the advisory details with USOM and Zyxel directly, and restrict network exposure of affected devices pending vendor guidance.
Sources
- NVD, CVE-2026-13206: https://nvd.nist.gov/vuln/detail/CVE-2026-13206
- Reference supplied with the CVE record (advisory TR-26-0799): https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0799; note that this host and path do not match USOM's own bulletin scheme (
https://www.usom.gov.tr/bildirim/tr-26-0799), so the link should be verified against USOM's site before being treated as the authoritative advisory.