Executive brief
A security vulnerability has been identified in various Zyxel networking devices, including routers, fiber modems, and Wi-Fi extenders. If an attacker gains administrative access to the device's management interface, they can execute unauthorized commands to take full control of the hardware. While this requires the attacker to already have valid administrator credentials, a successful exploit could lead to complete service disruption or interception of network traffic.
Technical details
This vulnerability (CWE-78) is a post-authentication command injection flaw located in the 'LogServer' field of the syslog component across multiple Zyxel product lines, including DSL/Ethernet CPE, Fiber ONTs, and Wireless Extenders. An attacker with network access to the management interface and valid administrator-level credentials can inject malicious OS commands via the LogServer configuration field. Successful exploitation grants the attacker full operating system-level access to the device. Zyxel has released firmware patches for all affected models; users are advised to update to the specific patch versions listed in the advisory (e.g., 5.17(ABPC.8)C0 for AX7501-B1).
Affected products
- Zyxel AX7501-B1 firmware through 5.17(ABPC.7.2)C0
- Zyxel DX3300-T0 / DX3300-T1 / DX3301-T0 / EX3300-T0 / EX3300-T1 / EX3301-T0 firmware through 5.50(ABVY.8)C0
- Zyxel DX4510-B0 / DX4510-B1 firmware through 5.17(ABYL.10.2)C0
- Zyxel DX5401-B1 / EX5401-B1 firmware through 5.17(ABYO.7.2)C0
- Zyxel EE3301-00 firmware through 5.63(ACMU.3.1)C0
- Zyxel EE5301-00 firmware through 5.63(ACLD.3.1)C0
- Zyxel EE6510-10 firmware through 5.19(ACJQ.4.2)C0
- Zyxel EMG3525-T50B / EMG5523-T50B / VMG3625-T50B / VMG8623-T50B firmware through 5.50(ABPM.9.8)C0
- Zyxel EX2210-T0 firmware through 5.50(ACDI.2.5)C0
- Zyxel EX3500-T0 / EX3501-T0 firmware through 5.44(ACHR.5.1)C0
- Zyxel EX3600-T0 firmware through 5.70(ACIF.2.1)C0
- Zyxel EX5512-T0 firmware through 5.70(ACEG.5.6)C0
- Zyxel EX5601-T0 / EX5601-T1 firmware through 5.70(ACDZ.6)C0
- Zyxel EX7501-B0 firmware through 5.18(ACHN.3.2)C0
- Zyxel EX7710-B0 firmware through 5.18(ACAK.1.7)C0
- Zyxel GM4100-B0 firmware through 5.18(ACCL.2.1)C0
- Zyxel VMG4005-B50A / VMG4005-B60A firmware through 5.17(ABQA.3.3)C0
- Zyxel AM7510-00 firmware through 5.63(ACOR.0.2)C0
- Zyxel PE3301-00 firmware through 5.63(ACMT.3.1)C0
- Zyxel PE5301-01 firmware through 5.63(ACOJ.3.1)C0
- Zyxel PM3100-T0 / PM5100-T0 / PM5100-T1 firmware through 5.42(ACBF.4.3)C0
- Zyxel PM7300-T0 firmware through 5.42(ABYY.4.1)C0
- Zyxel PM7500-00 firmware through 5.61(ACKK.1.4)C0
- Zyxel PX5301-T0 firmware through 5.44(ACKB.0.7)C0
- Zyxel WE3300-00 firmware through 5.70(ACKA.2)C0
- Zyxel WX3100-T0 firmware through 5.50(ABVL.5)C0
- Zyxel WX5600-T0 firmware through 5.70(ACEB.6)C0
Timeline
- 2026-07-21: advisory: Zyxel released the security advisory and patches.
- 2026-07-21: disclosed: CVE-2026-6952 published to NVD.