Summary
CVE-2026-13206 is an OS command injection vulnerability (CWE-78) in the Zyxel WAH7601 device. Because it is exploitable over the network without authentication or user interaction, it carries a CVSS v3.1 base score of 9.8 (Critical) and can allow an attacker to execute arbitrary operating system commands on an affected device.
Technical details
- Root cause: Improper neutralization of special elements used in an OS command — user-supplied input is passed to OS command execution without sufficient validation or sanitization.
- Trigger conditions: An attacker sends crafted input to the affected device; no authentication (PR:N) and no user interaction (UI:N) are required.
- Attack vector: Network (AV:N), low attack complexity (AC:L).
- Impact: Execution of arbitrary OS commands, with high impact to confidentiality, integrity, and availability.
Affected software
- Zyxel WAH7601, firmware versions through 20072026.
Severity
- CVSS v3.1 base score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: No fixed firmware version is confirmed in the CVE record. Consult Zyxel’s official security advisories and apply any vendor-provided firmware update for the WAH7601 as soon as it is available.
- If no patch: Restrict access to the device’s management/web interface so it is not reachable from untrusted networks or the internet, and limit management access to trusted hosts.

