Zyxel security advisory for command injection and improper authentication vulnerabilities in certain APs, FWA7, and Security Routers

CVEs: CVE-2026-6837, CVE-2026-8508
Summary

Zyxel has released patches for specific firmware versions of its APs, FWA7, and Security Routers. These updates address command injection and improper authentication vulnerabilities. Users are strongly advised to install the patches to ensure optimal protection.

What are the vulnerabilities?

CVE-2026-6837

A post-authentication command injection vulnerability in the "export-cgi" CGI program in certain AP firmware versions could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

CVE-2026-8508

An improper authentication vulnerability in the "social_login.cgi" CGI program in certain firmware versions of APs, FWA7, and Security Routers could allow an attacker on the WLAN to bypass captive portal authentication.

What versions are vulnerable—and what should you do?

Following a comprehensive investigation, we identified the affected firmware versions and released patches for models still within their vulnerability support period, as indicated in the tables below. Please note that on-market products not listed in the tables are not affected.


Table 1. Models affected by CVE-2026-6837
Product Affected model Affected version Patch availability
AP NWA50AX 7.10(ABYW.4)C0 and earlier 7.12(ABYW.0)C0
NWA50AX PRO 7.10(ACGE.4)C0 and earlier 7.12(ACGE.0)C0
NWA55AXE 7.10(ABZL.4)C0 and earlier 7.12(ABZL.0)C0
NWA55AX PRO 7.10(ACSP.5)C0 and earlier 7.12(ACSP.0)C0
NWA55AX PTP 7.10(ACSQ.5)C0 and earlier 7.12(ACSQ.0)C0
NWA90AX 7.10(ACCV.4)C0 and earlier 7.12(ACCV.0)C0
NWA90AX PRO 7.10(ACGF.5)C0 and earlier 7.12(ACGF.0)C0
NWA110AX 7.10(ABTG.4)C0 and earlier 7.12(ABTG.0)C0
NWA210AX 7.10(ABTD.4)C0 and earlier 7.12(ABTD.0)C0
NWA220AX-6E 7.10(ACCO.4)C0 and earlier 7.12(ACCO.0)C0
WAX300H 7.10(ACHF.4)C0 and earlier 7.12(ACHF.0)C0
WAX510D 7.10(ABTF.4)C0 and earlier 7.12(ABTF.0)C0
WAX610D 7.10(ABTE.4)C0 and earlier 7.12(ABTE.0)C0
WAX620D-6E 7.10(ACCN.4)C0 and earlier 7.12(ACCN.0)C0
WAX630S 7.10(ABZD.4)C0 and earlier 7.12(ABZD.0)C0
WAX640S-6E 7.10(ACCM.4)C0 and earlier 7.12(ACCM.0)C0
WAX650S 7.10(ABRM.4)C0 and earlier 7.12(ABRM.0)C0
WAX655E 7.10(ACDO.4)C0 and earlier 7.12(ACDO.0)C0
Table 2. Models affected by CVE-2026-8508
Product Affected model Affected version Patch availability
AP IAP500BE 7.30(ACPJ.4)C0 and earlier 7.40(ACPJ.1)C0
NWA30BE 7.30(ACPI.4)C0 and earlier 7.40(ACPI.1)C0
NWA50AX 7.10(ABYW.4)C0 and earlier 7.12(ABYW.0)C0
NWA50AX PRO 7.10(ACGE.4)C0 and earlier 7.12(ACGE.0)C0
NWA50BE 7.30(ACPB.4)C0 and earlier 7.40(ACPB.1)C0
NWA50BE PRO 7.30(ACPC.4)C0 and earlier 7.40(ACPC.1)C0
NWA55AXE 7.10(ABZL.4)C0 and earlier 7.12(ABZL.0)C0
NWA55AX PRO 7.10(ACSP.5)C0 and earlier 7.12(ACSP.0)C0
NWA55AX PTP 7.10(ACSQ.5)C0 and earlier 7.12(ACSQ.0)C0
NWA55BE 7.30(ACPH.4)C0 and earlier 7.40(ACPH.1)C0
NWA90AX 7.10(ACCV.4)C0 and earlier 7.12(ACCV.0)C0
NWA90AX PRO 7.10(ACGF.5)C0 and earlier 7.12(ACGF.0)C0
NWA90BE 7.30(ACPD.4)C0 and earlier 7.40(ACPD.1)C0
NWA90BE PRO 7.30(ACPE.4)C0 and earlier 7.40(ACPE.1)C0
NWA110AX 7.10(ABTG.4)C0 and earlier 7.12(ABTG.0)C0
NWA110BE 7.30(ACLZ.4)C0 and earlier 7.40(ACLZ.1)C0
NWA130BE 7.30(ACIL.4)C0 and earlier 7.40(ACIL.1)C0
NWA210AX 7.10(ABTD.4)C0 and earlier 7.12(ABTD.0)C0
NWA210AXv2 7.30(ACSR.4)C0 and earlier 7.40(ACSR.1)C0
NWA210BE 7.30(ACLY.4)C0 and earlier 7.40(ACLY.1)C0
NWA220AX-6E 7.10(ACCO.4)C0 and earlier 7.12(ACCO.0)C0
NWA240BE 7.30(ACQG.4)C0 and earlier 7.40(ACQG.1)C0
WAC500H 6.70(ABWA.6)C0 and earlier Hotfix is available upon request*
WAX300H 7.10(ACHF.4)C0 and earlier 7.12(ACHF.0)C0
WAX510D 7.10(ABTF.4)C0 and earlier 7.12(ABTF.0)C0
WAX610D 7.10(ABTE.4)C0 and earlier 7.12(ABTE.0)C0
WAX620D-6E 7.10(ACCN.4)C0 and earlier 7.12(ACCN.0)C0
WAX630S 7.10(ABZD.4)C0 and earlier 7.12(ABZD.0)C0
WAX640S-6E 7.10(ACCM.4)C0 and earlier 7.12(ACCM.0)C0
WAX650S 7.10(ABRM.4)C0 and earlier 7.12(ABRM.0)C0
WAX655E 7.10(ACDO.4)C0 and earlier 7.12(ACDO.0)C0
WBE530 7.35(ACLE.0)C0 and earlier 7.40(ACLE.1)C0
WBE510D 7.30(ACLX.4)C0 and earlier 7.40(ACLX.1)C0
WBE630S 7.30(ACLW.4)C0 and earlier 7.40(ACLW.1)C0
WBE660S 7.30(ACGG.4)C0 and earlier 7.40(ACGG.1)C0
WBE665S 7.35(ACQJ.0)C0 and earlier 7.40(ACQJ.1)C0
FWA7 FWA7 Leaf Plus 7.35(ACQK.0)C0 and earlier 7.40(ACQK.1)C0
FWA7 Root Plus 7.35(ACQL.0)C0 and earlier 7.40(ACQL.1)C0
Security Routers USG LITE 60AX 2.30(ACIP.1)C0 and earlier 2.40(ACIP.0)C0** in Sep. 2026

* Please reach out to your local Zyxel support team for the file.
** Updated by cloud.

Got a question?

Please contact your local service rep or visit Zyxel's Community for further information or assistance.

Acknowledgment

Thanks to Mina Nageh Salama for reporting the issue to us.

Revision history

2026-8-4: Initial release