Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3666 articles · 197852 vulns · 37/41 feeds (7d)
← Back to list
7.2
CVE-2026-6952PATCHED
zyxel · ax7501-b1 firmware

CVE-2026-6952: A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B

Description

A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

Affected Products

VendorProductVersions
zyxelax7501-b1 firmware<= 5.17(ABPC.7.2)C0

References

  • https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-post-authentication-command-injection-vulnerability-in-certain-dsl-ethernet-cpe-fiber-onts-and-wireless-extenders-07-21-2026(vendor-advisory)

Related News (1 articles)

Tier C
VulDB36d ago
CVE-2026-6952 | Zyxel AX7501-B1 up to 5.17(ABPC.7.2)C0 syslog os command injection
→ No new info (linked only)
CVSS 3.17.2 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-post-authentication-command-injection-vulnerability-in-certain-dsl-ethernet-cpe-fiber-onts-and-wireless-extenders-07-21-2026
CWECWE-78
PublishedJul 21, 2026
Last enriched36d agov2
Trending Score1
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-8508
CVE-2026-8508: An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug
Trending: 34
HIGHCVE-2026-6837
CVE-2026-6837: A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions
Trending: 18
CRITICALCVE-2026-13206
Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection
Trending: 7
HIGHCVE-2026-12984
Exposure of Sensitive Information to an Unauthorized Actor in Zyxel's WAH7601
Trending: 6
HIGHCVE-2026-6374
Hardcoded Credentials in Zyxel WAH7601 Router
Trending: 5

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Updated: severity, cvssEstimate
Jul 21, 2026
Patch Available
Jul 23, 2026

Version History

v2
Last enriched 36d ago
v2Tier C36d ago

Updated severity from HIGH to CRITICAL and adjusted CVSS estimate from 7.2 to 9.0 based on source classification as 'very critical'

severitycvssEstimate
via VulDB
v136d ago

Initial creation