CVE-2026-1460
Zyxel DX3301-T0 firmware, EX3301-T0 firmware, nebula fwa70 firmware
A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
- CVSS
- 7.2
- EPSS
- 1.16% 63.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.28