{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/ax7501-b1-firmware/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-6952"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AX7501-B1 firmware"],"_cs_severities":["high"],"_cs_tags":["command-injection","vulnerability","router","network-device"],"_cs_type":"advisory","_cs_vendors":["Zyxel"],"content_html":"\u003cp\u003eA critical post-authentication command injection vulnerability, tracked as CVE-2026-6952, has been discovered in the \u0026quot;LogServer\u0026quot; field of the syslog component within Zyxel AX7501-B1 router firmware versions up to and including 5.17(ABPC.7.2)C0. This flaw allows an authenticated attacker possessing administrative credentials to execute arbitrary operating system commands on the affected device. This means an attacker who has already gained access to the device's administration interface can leverage this vulnerability to achieve full control, potentially installing malicious software, altering device configurations, or gaining further access to the internal network segments connected to the router. The vulnerability stems from improper neutralization of special elements used in OS commands, making it susceptible to injection when the LogServer field is configured. This vulnerability is of high concern for organizations and home users utilizing Zyxel AX7501-B1 devices, as it bypasses existing security controls once an attacker has authenticated.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains valid administrative credentials for a Zyxel AX7501-B1 device.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates to the device's web management interface.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the syslog configuration settings within the administrative interface.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious payload containing OS commands, leveraging special characters for injection.\u003c/li\u003e\n\u003cli\u003eAttacker injects this malicious payload into the \u0026quot;LogServer\u0026quot; field during syslog configuration.\u003c/li\u003e\n\u003cli\u003eThe device processes the updated syslog configuration, which improperly executes the injected OS commands.\u003c/li\u003e\n\u003cli\u003eThe attacker gains remote command execution on the Zyxel AX7501-B1 device with administrative privileges.\u003c/li\u003e\n\u003cli\u003eAttacker can then proceed to compromise the device fully, leading to potential network persistence or further internal network access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-6952 grants an authenticated attacker the ability to execute arbitrary operating system commands on the Zyxel AX7501-B1 device. This leads to full compromise of the network router, allowing attackers to manipulate network traffic, establish persistence, deploy additional malware, or pivot into the internal network. Organizations or individuals using affected Zyxel AX7501-B1 devices could face severe consequences, including data exfiltration, network disruption, and unauthorized access to connected systems, potentially affecting critical business operations or personal data privacy.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-6952 immediately by upgrading Zyxel AX7501-B1 firmware to a version beyond 5.17(ABPC.7.2)C0, as advised in the Zyxel Corporation security advisory linked in the references.\u003c/li\u003e\n\u003cli\u003eImplement strong, unique passwords for all administrative accounts on network devices to prevent initial authentication.\u003c/li\u003e\n\u003cli\u003eRegularly review syslog configurations on network devices for any unauthorized or suspicious modifications.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-21T03:18:19Z","date_published":"2026-07-21T03:18:19Z","id":"https://feed.craftedsignal.io/briefs/2026-07-zyxel-cve-2026-6952/","summary":"A post-authentication command injection vulnerability (CVE-2026-6952) in the \"LogServer\" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 allows an authenticated attacker with administrator privileges to execute arbitrary OS commands on the affected device.","title":"Zyxel AX7501-B1 Firmware Command Injection (CVE-2026-6952)","url":"https://feed.craftedsignal.io/briefs/2026-07-zyxel-cve-2026-6952/"}],"language":"en","title":"CraftedSignal Threat Feed - AX7501-B1 Firmware","version":"https://jsonfeed.org/version/1.1"}