What is CVE-2026-6837?
CVE-2026-6837 is an authenticated command injection vulnerability in Zyxel's PKCS#12 certificate export flow, specifically within the `export-cgi` component. This flaw allows an authenticated user to execute arbitrary commands. Affected firmware versions require vendor-provided updates for mitigation.
Azərbaycanca: CVE-2026-6837 Zyxel cihazlarında PKCS#12 sertifikat ixracı zamanı autentifikasiya olunmuş əmr inyeksiyası zəifliyidir. Bu boşluq `export-cgi` komponentində yerləşir və təsdiqlənmiş istifadəçiyə əmr icra etməyə imkan verir. Təsirə məruz qalan firmware versiyaları üçün istehsalçı tərəfindən yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
In which component of Zyxel devices is CVE-2026-6837 located?
This vulnerability is located in the `export-cgi` component of Zyxel devices.
Does an attacker need to be authenticated to exploit CVE-2026-6837?
Yes, an attacker must be an authenticated user to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.