Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.2

CVE-2026-6952: Zyxel AX7501-B1: Malicious Commands via Log Server

CVE-2026-6952 CVE-2026-6952
Summary

An attacker with admin access can run malicious commands on a Zyxel AX7501-B1 router if it's configured to send logs to a specific server. This could allow the attacker to take control of the router or disrupt its function. Update the router's firmware to the latest version to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
zyxel ax7501-b1 firmware <= 5.17(ABPC.7.2)C0
Original title
A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated att...
Original description
A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
mitre CVSS3.1 7.2
Vulnerability type
CWE-78 OS Command Injection
Published: 21 Jul 2026 · Updated: 21 Jul 2026 · First seen: 21 Jul 2026