External risk intelligence

Zyxel WAH7601 OS Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-13206

The affected product is a portable wireless router (WAH7601). Such devices are commonly deployed at the edge of networks to provide internet connectivity, making their management interfaces or web-based configuration portals frequently accessible over network connections.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Zyxel Networks WAH7601 could allow an attacker to run unauthorized commands on the device, potentially leading to a compromise of its operations.

  • Unauthenticated remote command execution.
  • Critical flaw in network edge devices.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted command to the affected Zyxel device over the network. This could occur if the device's interface is exposed to the internet or an untrusted network. Successful exploitation allows an attacker to execute arbitrary operating system commands, potentially leading to a complete compromise of the device.

  • Accessible over the network.
  • Special characters in OS command.
  • Arbitrary OS command execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to execute arbitrary operating system commands on the affected device. When supported by the advisory, this could occur when an attacker sends specially crafted input to the device's network interfaces, potentially leading to unauthorized system access or modification.

  • System commands could be injected.
  • Network access enables command execution.
  • Unaffected system data integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Zyxel WAH7601 devices presents a critical risk due to OS command injection. Owners of these devices, likely managed by network infrastructure or dedicated appliance teams, must first determine the scope of affected hardware. This involves identifying all WAH7601 units, assessing their network exposure, and confirming business criticality to prioritize remediation efforts.

  • Network or appliance teams should own this.
  • Verify device reachability and criticality first.
  • Plan remediation based on identified exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Zyxel WAH7601?

The Zyxel WAH7601 is a portable 4G LTE wireless router designed to provide mobile internet connectivity. It functions as a network gateway, allowing devices to connect to the internet over cellular data, often serving as a primary or backup network edge component.

What does OS command injection mean for CVE-2026-13206?

This vulnerability, classified as CWE-78, occurs when software fails to properly filter special characters in user input before passing it to the operating system. Because of this, an attacker can append their own unauthorized commands to legitimate system functions, forcing the device to execute unintended actions.

How can an attacker trigger this vulnerability?

An attacker triggers this flaw by sending specially crafted network requests containing malicious input to the device. The vulnerability is not triggered by standard, legitimate traffic or normal web browsing; it specifically requires the submission of malformed data that the device fails to sanitize.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal indicates that because the WAH7601 is a router, it is frequently deployed at the edge of networks where management portals may be reachable over the internet. Devices exposed to untrusted networks or the public internet face a significantly higher risk of exploitation compared to those kept on isolated, internal segments.

What steps should I take if I use this router?

Begin by auditing your network to identify all active WAH7601 units. Evaluate which devices are accessible from the internet versus those limited to internal management, then prioritize the most exposed units for immediate review while you await official guidance or security updates from Zyxel.

References