PT-2025-10684 · Zyxel · Zyxel Ex5601-T1

Dawid Kulikowski

·

Published

2025-03-11

·

Updated

2025-03-12

·

CVE-2024-12009

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zyxel EX5601-T1 firmware version V5.70(ACDZ.3.6)C0 and earlier
Description A post-authentication command injection issue in the ZyEE function could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
Recommendations For Zyxel EX5601-T1 firmware versions V5.70(ACDZ.3.6)C0 and earlier, consider restricting access to the ZyEE function until a patch is available.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-05042
CVE-2024-12009

Affected Products

Zyxel Ex5601-T1