
CVE-2026-6837: Authenticated Command Injection Vulnerability in Zyxel PKCS#12 Export Functionality
CybersecurityVulnerabilitiesHackingNetworkSecurity
This post describes CVE-2026-6837, an authenticated command-injection vulnerability in Zyxel’s PKCS#12 certificate export functionality. It details the vulnerable execution path, the root cause of the flaw, and the range of affected firmware versions. The analysis also includes the firmware-emulation methodology used during the investigation.