PT-2026-61820 · Zyxel · Ax7501-B1
CVE-2026-6952
·
Published
2026-07-21
·
Updated
2026-07-23
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zyxel AX7501-B1 versions prior to 5.17(ABPC.7.2)C0
Description
A post-authentication command injection issue exists within the syslog component. An authenticated attacker with administrator privileges can execute arbitrary operating system commands by manipulating the
LogServer field.Recommendations
Update Zyxel AX7501-B1 to a version newer than 5.17(ABPC.7.2)C0.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ax7501-B1