Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 28 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Post‑authentication command injection in Zyxel DX3300‑T0 EasyMesh APIs |
Tue, 28 Apr 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zyxel
Zyxel dx3300-t0 Firmware |
|
| Vendors & Products |
Zyxel
Zyxel dx3300-t0 Firmware |
Tue, 28 Apr 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS commands on an affected device. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zyxel
Published:
Updated: 2026-04-29T03:55:39.766Z
Reserved: 2026-01-08T08:42:15.633Z
Link: CVE-2026-0711
Updated: 2026-04-28T12:57:27.371Z
Status : Awaiting Analysis
Published: 2026-04-28T03:16:02.167
Modified: 2026-04-28T20:11:56.713
Link: CVE-2026-0711
No data.
OpenCVE Enrichment
Updated: 2026-04-28T12:45:31Z