Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223853 vulns · 37/41 feeds (7d)
← Back to list
7.2
CVE-2026-6952PATCHED
zyxel · ax7501-b1 firmware

CVE-2026-6952: A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B

Description

A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

Affected Products

VendorProductVersions
zyxelax7501-b1 firmware<= 5.17(ABPC.7.2)C0

References

  • https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-post-authentication-command-injection-vulnerability-in-certain-dsl-ethernet-cpe-fiber-onts-and-wireless-extenders-07-21-2026(vendor-advisory)

Related News (1 articles)

Tier C
VulDB69d ago
CVE-2026-6952 | Zyxel AX7501-B1 up to 5.17(ABPC.7.2)C0 syslog os command injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.2 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-post-authentication-command-injection-vulnerability-in-certain-dsl-ethernet-cpe-fiber-onts-and-wireless-extenders-07-21-2026
CWECWE-78
PublishedJul 21, 2026
Last enriched69d agov2
Trending Score0
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-8508
CVE-2026-8508: An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug
Trending: 2
HIGHCVE-2026-6837
CVE-2026-6837: A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions
Trending: 1
HIGHCVE-2026-14818
CVE-2026-14818: A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versi
CRITICALCVE-2026-13206
Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection
HIGHCVE-2026-6374
Hardcoded Credentials in Zyxel WAH7601 Router

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Updated: severity, cvssEstimate
Jul 21, 2026
Patch Available
Jul 23, 2026

Version History

v2
Last enriched 69d ago
v2Tier C69d ago

Updated severity from HIGH to CRITICAL and adjusted CVSS estimate from 7.2 to 9.0 based on source classification as 'very critical'

severitycvssEstimate
via VulDB
v169d ago

Initial creation