Description
A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A post‑authentication command injection vulnerability exists in the LogServer field of the syslog component in Zyxel AX7501‑B1 firmware versions through 5.17(ABPC.7.2)C0. If an attacker is authenticated with administrator privileges, the flaw permits execution of arbitrary operating‑system commands on the device. The weakness corresponds to CWE‑78: Improper Neutralization of Special Elements used in a Command ('Command Injection'). This allows the attacker to compromise the device’s integrity and potentially pivot to other assets on the local network.

Affected Systems

Zyxel AX7501‑B1 firmware versions through 5.17(ABPC.7.2)C0 are affected. No other Zyxel products or firmware releases are listed as vulnerable.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity, while the EPSS of less than 1% suggests a low probability of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to first authenticate and obtain administrator privileges, after which they can manipulate the LogServer field to inject commands. Prevention relies on firmware updates or configuration restrictions to mitigate the attack surface.

Generated by OpenCVE AI on July 30, 2026 at 18:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a firmware update that removes the vulnerable LogServer field or hardens its handling, ensuring the device is on a version later than 5.17(ABPC.7.2)C0.
  • If an update is not immediately available, disable the syslog component or remove the LogServer configuration to block injection attempts.
  • Maintain strict access control by ensuring only trusted users have administrator rights and enforce the principle of least privilege on the device.

Generated by OpenCVE AI on July 30, 2026 at 18:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Post‑Authentication Command Injection via Syslog LogServer Field in Zyxel AX7501‑B1 Firmware

Mon, 27 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Post-Authentication Command Injection in Zyxel AX7501‑B1 Firmware

Sun, 26 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Post-Authentication Command Injection in Zyxel AX7501‑B1 Firmware

Wed, 22 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Zyxel
Zyxel ax7501-b1 Firmware
Vendors & Products Zyxel
Zyxel ax7501-b1 Firmware

Tue, 21 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Description A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zyxel Ax7501-b1 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published:

Updated: 2026-07-23T03:56:26.499Z

Reserved: 2026-04-24T08:08:46.958Z

Link: CVE-2026-6952

cve-icon Vulnrichment

Updated: 2026-07-21T13:20:18.273Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T18:15:13Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')