Impact
A post‑authentication command injection vulnerability exists in the LogServer field of the syslog component in Zyxel AX7501‑B1 firmware versions through 5.17(ABPC.7.2)C0. If an attacker is authenticated with administrator privileges, the flaw permits execution of arbitrary operating‑system commands on the device. The weakness corresponds to CWE‑78: Improper Neutralization of Special Elements used in a Command ('Command Injection'). This allows the attacker to compromise the device’s integrity and potentially pivot to other assets on the local network.
Affected Systems
Zyxel AX7501‑B1 firmware versions through 5.17(ABPC.7.2)C0 are affected. No other Zyxel products or firmware releases are listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity, while the EPSS of less than 1% suggests a low probability of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to first authenticate and obtain administrator privileges, after which they can manipulate the LogServer field to inject commands. Prevention relies on firmware updates or configuration restrictions to mitigate the attack surface.
OpenCVE Enrichment