[CVE-2026-3870, CVE-2026-3871] Vulnerability Fix

Options
Zyxel_CSO
Zyxel_CSO Posts: 524 image  Zyxel Employee
5 Answers First Comment Friend Collector Ninth Anniversary

CVE ID

  • CVE-2026-3870
  • CVE-2026-3871

Affected model & Version

Model

Version

Vulnerability Fix Version

Nebula LTE3301-PLUS

1.18(ACCA.6)C0 and earlier

*1.18(ACCA.8)V0

Nebula NR7101

1.16(ACCC.1)C0 and earlier

*1.16(ACCC.3)V0

* : Provided upon request. Please ensure you are aware of the following session below.


Important Notes & Warnings

  • Mobile routers operate over cellular networks, which are typically deployed behind Internet Service Provider Carrier-Grade NAT (CGNAT).As a result, the practical exploitation risk of this vulnerability is considered low in typical deployment scenarios. The V0 vulnerability fix firmware for the Nebula LTE3301-PLUS and Nebula NR7101 models is provided exclusively for users with urgent security concerns.

    ⚠️ Important: Upgrading to the security fix firmware will disable Nebula cloud management functionality

Before upgrading, please ensure a complete configuration backup is performed: Maintenance > Backup/Restore

Requesting the Fix Firmware

Please carefully review the "Important Notes & Warnings" section above and ensure you fully understand the impact, including the loss of Nebula cloud management after upgrading.

If you accept these limitations and still require the vulnerability fix firmware, please create a post to request the vulnerability fix firmware at:

🔗Wireless - Zyxel Community

We will assist accordingly.

Zyxel Nebula Support