CVE-2026-13206Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection. This issue affects WAH7601: through 20072026.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-10: 3Technical Details · 2026-08-10: 308-10
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • ThreatAft@ThreatAft
    Disclosure

    🚨 Zyxel WAH7601 4-CVE Bundle — NO PATCH CVE-2026-13206 (9.8): Unauthenticated RCE CVE-2026-12984 (8.2): Credential exposure CVE-2026-6374 (7.3): Hardcoded creds CVE-2026-6373 (6.5): Info disclosure → http://threataft.com/articles/zyxel-wah7601-4-cve-bundle #cybersecurity #Zyxel #RouterSecurity #ThreatIntel

    Post summary

    The post announces a bundle of four recently disclosed CVEs affecting Zyxel WAH7601 routers, providing severity scores and vulnerability types, and notes the lack of a patch, without supplying PoC or exploit details.

    0000063
    36 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13206 Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection. This … https://www.cve.org/CVERecord?id=CVE-2026-13206 ----- Traducción: CVE-2026-13206 Neu… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-13206 as an OS command injection flaw in Zyxel WAH7601 caused by improper neutralization, with no PoC, tool, active exploitation, or patch information provided.

    0000039
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-13206 Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection. This … https://www.cve.org/CVERecord?id=CVE-2026-13206

    Post summary

    The snippet provides the CVE identifier and a concise technical description of an OS command injection flaw in Zyxel WAH7601, with no mention of PoC, exploit, or patches.

    000001.1K
    57.9K followersView on X

Explore more