Zyxel security advisory (AV26-725)
Serial number: AV26-725 Date: July 21, 2026 On July 21, 2026, Zyxel published a security advisory to address a vulnerability in the following products: DSL/Ethernet CPE – multiple versions and models Fiber ONTs – multiple versions and models Wireless Extenders – multiple versions and models The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. Zyxel security advisory for post-authentication command injection vulnerability in certain DSL/Ethernet CPE, Fiber ONTs, and Wireless Extenders Zyxel Advisories
CSIRTS triage
- What
- A post-authentication command injection vulnerability exists in certain Zyxel products.
- Who is affected
- Users and administrators of affected DSL/Ethernet CPE, Fiber ONTs, and Wireless Extenders.
- Urgency
- Remediation is necessary to prevent potential exploitation, although the severity is unknown.
- Action
- Review the advisory and apply the necessary updates.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch DSL/Ethernet CPE, Fiber ONTs, Wireless Extenders
Get an email when a new DSL/Ethernet CPE, Fiber ONTs, Wireless Extenders advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/zyxel-security-advisory-av26-725
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30