CVE-2026-1459: Zyxel DX5401-b1 Firmware
High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.
A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on an affected device.
Affected products
- Zyxel DX5401-b1 Firmware: up to and including 5.17\(abyo.7.1\)c0
- Zyxel EMG3525-t50b Firmware: up to and including 5.50\(abpm.9.7\)c0
- Zyxel EMG5523-t50b Firmware: up to and including 5.50\(abpm.9.7\)c0
- Zyxel VMG3625-t50b Firmware: up to and including 5.50\(abpm.9.7\)c0
- Zyxel VMG3625-t50c Firmware: up to and including 5.50\(abpm.9.7\)c0
- Zyxel VMG8623-t50b Firmware: up to and including 5.50\(abpm.9.7\)c0
Published 2026-02-24. Last modified 2026-06-17.