Back

HIGH

A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device

Published Jul 21, 2026

Description

A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Zyxel
Published Jul 21, 2026
Updated Jul 23, 2026
Reserved Apr 24, 2026
CISA Vulnrichment
Updated Jul 21, 2026
NVD
Status Awaiting Analysis
Modified Jul 23, 2026
Red Hat
Severity n/a
Public date n/a