A vulnerability classified as very critical has been found in Zyxel WAX650S up to 7.10(ABRM.4)C0. This issue affects some unknown processing of the file export.cgi of the component export-cgi. This manipulation causes os command injection.

This vulnerability is handled as CVE-2026-6837. The attack can be initiated remotely. There is not any exploit available.