CVE-2026-6952

A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
Configurations

No configuration.

History

21 Jul 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-21 03:16

Updated : 2026-07-23 05:16


NVD link : CVE-2026-6952

Mitre link : CVE-2026-6952

CVE.ORG link : CVE-2026-6952


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')