SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-6952

HIGH · CVSS 7.2 EPSS 0.95%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

A post-authentication command injection vulnerability exists in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions up to 5.17(ABPC.7.2)C0, allowing authenticated administrators to execute arbitrary OS commands. This could lead to unauthorized system control and potential data breaches. Organizations using this firmware should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-6952
Severity
HIGH
CVSS
7.2
EPSS
0.95%

Original NVD Description

A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.