PT-2025-10685 · Zyxel · Zyxel Ax7501-B1
Martin Wrona
·
Published
2025-03-11
·
Updated
2025-03-12
·
CVE-2024-12010
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Zyxel AX7501-B1 firmware versions prior to V5.17(ABPC.5.3)C0
Description
A post-authentication command injection issue in the
zyUtilMailSend function could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.Recommendations
For Zyxel AX7501-B1 firmware versions prior to V5.17(ABPC.5.3)C0, consider disabling the
zyUtilMailSend function until a patch is available to prevent potential command injection attacks.Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel Ax7501-B1