CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Zyxel security advisory (AV26-725)

unknown
Serial number: AV26-725 Date: July 21, 2026 On July 21, 2026, Zyxel published a security advisory to address a vulnerability in the following products: DSL/Ethernet CPE – multiple versions and models Fiber ONTs – multiple versions and models Wireless Extenders – multiple versions and models The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. Zyxel security advisory for post-authentication command injection vulnerability in certain DSL/Ethernet CPE, Fiber ONTs, and Wireless Extenders Zyxel Advisories

CSIRTS triage

What
A post-authentication command injection vulnerability exists in certain Zyxel products.
Who is affected
Users and administrators of affected DSL/Ethernet CPE, Fiber ONTs, and Wireless Extenders.
Urgency
Remediation is necessary to prevent potential exploitation, although the severity is unknown.
Action
Review the advisory and apply the necessary updates.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch DSL/Ethernet CPE, Fiber ONTs, Wireless Extenders

Get an email when a new DSL/Ethernet CPE, Fiber ONTs, Wireless Extenders advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-07-21
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/zyxel-security-advisory-av26-725

More from Canadian Centre for Cyber Security