PT-2025-10685 · Zyxel · Zyxel Ax7501-B1
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Zyxel AX7501-B1 firmware versions prior to V5.17(ABPC.5.3)C0
Description
A post-authentication command injection issue in the
zyUtilMailSend function could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.Recommendations
For Zyxel AX7501-B1 firmware versions prior to V5.17(ABPC.5.3)C0, consider disabling the
zyUtilMailSend function until a patch is available to prevent potential command injection attacks.Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel Ax7501-B1