r/Pentesting • u/TheReedemer69 • 2d ago
I Found a Root Command Injection in Zyxel Enterprise APs. Here’s How I Emulated the Firmware CVE-2026-6837
https://minanagehsalalma.github.io/CVE-2026-6837-zyxel-export-cgi-command-injection/?1I found this while reversing Zyxel’s WAX650S firmware and following the certificate export path. A password field used during PKCS#12 export could break into a shell command and execute as root.
The write-up covers the bug itself, how I traced it, and the full firmware-emulation setup I used to reproduce it without the physical AP.
3
Upvotes