# CVE-2026-7257

## Summary

- **CVE ID:** CVE-2026-7257
- **Severity:** MEDIUM
- **CVSS Score:** 4.4 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-922
- **Published:** May 12, 2026
- **Last Modified:** May 12, 2026

## Description

** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow a local attacker with administrator privileges to download and decrypt a backup configuration file.

## Affected Products

- Zyxel — WRE6505 v2 firmware (V1.00(ABDV.3)C0)

## References

- [CNA](https://www.zyxel.com/global/en/support/end-of-life)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.11%
- **EPSS Percentile:** 1.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._