Review reviewHigh

CVE-2026-1460

Zyxel DX3301-T0 firmware, EX3301-T0 firmware, nebula fwa70 firmware

A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

CVSS
7.2
EPSS
1.16%
63.9% percentile
CISA KEV
Not listed
Published
2026.04.28
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability1.16%
Technical severityCVSS 7.2

Vulnerability overview

A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

Affected product and versions

Product
Zyxel DX3301-T0 firmware, EX3301-T0 firmware, nebula fwa70 firmware
Affected versions
>= <= 5.50(ABVY.7.1)C0, < 1.51\(acrf.0\)v0, < 1.60\(acko.3\)v0, < 1.60\(acgd.1\)v0, < 1.60\(acpz.1\)v0, < 1.60\(acgc.2\)v0, < 1.18\(acca.7\)v0, < 1.15\(acev.4\)v0, < 1.16\(accg.1\)v0, < 1.16\(accc.2\)v0, < 5.50\(abvy.7.2\)c0, < 5.17\(abyo.7.2\)c0, < 5.63\(acmu.3.1\)c0, < 5.63\(acld.3.1\)c0, < 5.19\(acjq.4.2\)c0, < 5.50\(abpm.9.8\)c0, < 5.50\(acdi.2.5\)c0, < 5.44\(achr.6\)c0, < 5.70\(acif.3\)c0, < 5.70\(aceg.5.5\)c0
Fixed versions
1.51\(acrf.0\)v0, 1.60\(acko.3\)v0, 1.60\(acgd.1\)v0, 1.60\(acpz.1\)v0, 1.60\(acgc.2\)v0, 1.18\(acca.7\)v0, 1.15\(acev.4\)v0, 1.16\(accg.1\)v0, 1.16\(accc.2\)v0, 5.50\(abvy.7.2\)c0, 5.17\(abyo.7.2\)c0, 5.63\(acmu.3.1\)c0, 5.63\(acld.3.1\)c0, 5.19\(acjq.4.2\)c0, 5.50\(abpm.9.8\)c0, 5.50\(acdi.2.5\)c0, 5.44\(achr.6\)c0, 5.70\(acif.3\)c0, 5.70\(aceg.5.5\)c0, 5.70\(acdz.6\)c0

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Zyxel DX3301-T0 firmware, EX3301-T0 firmware, nebula fwa70 firmware and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-78