Zyxel AX7501-B1 Firmware Command Injection (CVE-2026-6952)
A post-authentication command injection vulnerability (CVE-2026-6952) in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 allows an authenticated attacker with administrator privileges to execute arbitrary OS commands on the affected device.
A critical post-authentication command injection vulnerability, tracked as CVE-2026-6952, has been discovered in the "LogServer" field of the syslog component within Zyxel AX7501-B1 router firmware versions up to and including 5.17(ABPC.7.2)C0. This flaw allows an authenticated attacker possessing administrative credentials to execute arbitrary operating system commands on the affected device. This means an attacker who has already gained access to the device's administration interface can leverage this vulnerability to achieve full control, potentially installing malicious software, altering device configurations, or gaining further access to the internal network segments connected to the router. The vulnerability stems from improper neutralization of special elements used in OS commands, making it susceptible to injection when the LogServer field is configured. This vulnerability is of high concern for organizations and home users utilizing Zyxel AX7501-B1 devices, as it bypasses existing security controls once an attacker has authenticated.
Attack Chain
- Attacker obtains valid administrative credentials for a Zyxel AX7501-B1 device.
- Attacker authenticates to the device's web management interface.
- Attacker navigates to the syslog configuration settings within the administrative interface.
- Attacker crafts a malicious payload containing OS commands, leveraging special characters for injection.
- Attacker injects this malicious payload into the "LogServer" field during syslog configuration.
- The device processes the updated syslog configuration, which improperly executes the injected OS commands.
- The attacker gains remote command execution on the Zyxel AX7501-B1 device with administrative privileges.
- Attacker can then proceed to compromise the device fully, leading to potential network persistence or further internal network access.
Impact
Successful exploitation of CVE-2026-6952 grants an authenticated attacker the ability to execute arbitrary operating system commands on the Zyxel AX7501-B1 device. This leads to full compromise of the network router, allowing attackers to manipulate network traffic, establish persistence, deploy additional malware, or pivot into the internal network. Organizations or individuals using affected Zyxel AX7501-B1 devices could face severe consequences, including data exfiltration, network disruption, and unauthorized access to connected systems, potentially affecting critical business operations or personal data privacy.
Recommendation
- Patch CVE-2026-6952 immediately by upgrading Zyxel AX7501-B1 firmware to a version beyond 5.17(ABPC.7.2)C0, as advised in the Zyxel Corporation security advisory linked in the references.
- Implement strong, unique passwords for all administrative accounts on network devices to prevent initial authentication.
- Regularly review syslog configurations on network devices for any unauthorized or suspicious modifications.