CVE-2026-6373
MEDIUMCVSS 6.5/10EPSS 0.17%
Last modified
CVE-2026-6373 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allows Web Application Fingerprinting. This issue affects WAH7601: through 20072026.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allows Web Application Fingerprinting. This issue affects WAH7601: through 20072026.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Zyxel Networks | WAH7601 | <= 20072026 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-6373?
Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allows Web Application Fingerprinting.
This issue affects WAH7601: through 20072026.
How severe is CVE-2026-6373?
CVE-2026-6373 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2026-6373?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-63723Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-63725sysPass's FileBackupService::doBackupFiles() in lib/SP/Servi…7.2
- CVE-2026-63726Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-63727Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 …8.8
- CVE-2026-63728Gitleaks prior to 8.30.1 contains a template injection vulne…8.1
- CVE-2026-63729The SyncTeX parser (synctex_parser.c) shipped with TeX Live …6.8
- CVE-2026-63730HyperDX before 2.31.0 contains a server-side request forgery…5.3
- CVE-2026-63731HyperDX before 2.31.0 contains a server-side request forgery…7.7
- CVE-2026-637329router 0.4.59 (fixed in 0.4.60) contains a chain of vulnera…9.9
- CVE-2026-63733SurrealDB versions before 3.2.0 contain a permissions bypass…6.5
- CVE-2026-63734SurrealDB versions before 3.2.0 contain a denial of service …6.9
- CVE-2026-63735SurrealDB versions before 3.2.0 fail to validate namespace a…8.6
Are you affected by CVE-2026-6373?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
