A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
| Vendor | Product | Versions |
|---|---|---|
| zyxel | ax7501-b1 firmware | <= 5.17(ABPC.7.2)C0 |
Updated severity from HIGH to CRITICAL and adjusted CVSS estimate from 7.2 to 9.0 based on source classification as 'very critical'
Initial creation