GHSA-957w-jr89-h22xHighCVSS 7.2
A post-authentication command injection vulnerability in the "LogServer" field of the syslog...
🔗 CVE IDs covered (1)
📋 Description
A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
🔗 References (3)
- https://nvd.nist.gov/vuln/detail/CVE-2026-6952
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-post-authentication-command-injection-vulnerability-in-certain-dsl-ethernet-cpe-fiber-onts-and-wireless-extenders-07-21-2026
- https://github.com/advisories/GHSA-957w-jr89-h22x